Missing validation of access permissions in WWBN AVideo by WWBN
CVE-2026-90546
5.3MEDIUM
What is CVE-2026-90546?
WWBN AVideo lacks proper validation of access permissions within the like.json.php endpoint, enabling authorized users to submit likes on password-protected and group-restricted videos. This vulnerability allows malicious actors to manipulate like counts by submitting requests for videos they should not have access to, thus circumventing the established access controls. Users and administrators are advised to review configurations and apply necessary patches to protect against unauthorized interactions with video content.
Affected Version(s)
AVideo 0
