Authorization Bypass in WWBN AVideo Affects Video Access Controls
CVE-2026-90545

5.3MEDIUM

Key Information:

Vendor

Wwbn

Status
Vendor
CVE Published:
12 September 2026

What is CVE-2026-90545?

WWBN AVideo has a vulnerability that compromises video access permissions within the commentAddNew.json.php endpoint. This issue allows authenticated users to post comments on videos that are password-protected or restricted to groups, effectively bypassing the defined access controls. Attackers can exploit this flaw by sending POST requests with a valid session, gaining the ability to comment on content they should not have access to. This vulnerability emphasizes the importance of secure authorization checks in web applications to prevent unauthorized interactions.

Affected Version(s)

AVideo 0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

santhreal
.