Authorization Bypass in WWBN AVideo Affects Video Access Controls
CVE-2026-90545
5.3MEDIUM
What is CVE-2026-90545?
WWBN AVideo has a vulnerability that compromises video access permissions within the commentAddNew.json.php endpoint. This issue allows authenticated users to post comments on videos that are password-protected or restricted to groups, effectively bypassing the defined access controls. Attackers can exploit this flaw by sending POST requests with a valid session, gaining the ability to comment on content they should not have access to. This vulnerability emphasizes the importance of secure authorization checks in web applications to prevent unauthorized interactions.
Affected Version(s)
AVideo 0
