Authentication Bypass in AVideo by WWBN
CVE-2026-89251

7.1HIGH

Key Information:

Vendor

Wwbn

Status
Vendor
CVE Published:
11 September 2026

What is CVE-2026-89251?

AVideo fails to properly validate ad impressions, specifically within the AD_Server/log.php file. This oversight allows authenticated users to craft arbitrary label values, leading to unauthorized minting of wallet credits for campaign video owners. Attackers exploit this flaw by repeatedly sending POST requests with label details, which erroneously trigger credit for ads that may not have been legitimately viewed. The lack of necessary verification undermines the integrity of the wallet credit system, potentially resulting in financial losses for video campaign owners.

Affected Version(s)

AVideo 0

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

santhreal
.