Authentication Bypass in AVideo by WWBN
CVE-2026-89251
7.1HIGH
What is CVE-2026-89251?
AVideo fails to properly validate ad impressions, specifically within the AD_Server/log.php file. This oversight allows authenticated users to craft arbitrary label values, leading to unauthorized minting of wallet credits for campaign video owners. Attackers exploit this flaw by repeatedly sending POST requests with label details, which erroneously trigger credit for ads that may not have been legitimately viewed. The lack of necessary verification undermines the integrity of the wallet credit system, potentially resulting in financial losses for video campaign owners.
Affected Version(s)
AVideo 0
