Unrestricted Authentication Vulnerability in WWBN AVideo
CVE-2026-86729
9.1CRITICAL
What is CVE-2026-86729?
WWBN AVideo exposes a significant vulnerability through the get_api_preauthorize endpoint in its API, which allows brute-force attempts without any rate limiting. Unlike its counterpart, get_api_signIn, which restricts login attempts, this endpoint permits unlimited guesses on user credentials. The response mechanism further complicates security; it reveals whether a user ID is authenticated or not, in addition to returning the same 'Invalid credentials' message for both successful and failed login attempts. As a result, this flaw could lead to unauthorized access to user accounts, including admin accounts, posing a serious security risk for users of AVideo.
Affected Version(s)
AVideo 0 <= 29.0
