Access Control Flaw in WWBN AVideo Product
CVE-2026-90544

5.3MEDIUM

Key Information:

Vendor

Wwbn

Status
Vendor
CVE Published:
12 September 2026

What is CVE-2026-90544?

The AVideo platform by WWBN is affected by a significant access control vulnerability that enables authenticated attackers to manipulate video viewing statistics. The issue arises in the videoAddViewCount.json.php endpoint, which fails to adequately validate user permissions before updating the view count and watch-time data for videos. By submitting requests containing arbitrary video IDs, an attacker can increment view counts on videos they should not have access to, potentially skewing analytics and impacting content creators. This vulnerability emphasizes the importance of implementing strict validation measures within user-accessed endpoints.

Affected Version(s)

AVideo 0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

santhreal
.