Missing validation of access permissions in WWBN AVideo by WWBN
CVE-2026-90546

5.3MEDIUM

Key Information:

Vendor

Wwbn

Status
Vendor
CVE Published:
12 September 2026

What is CVE-2026-90546?

WWBN AVideo lacks proper validation of access permissions within the like.json.php endpoint, enabling authorized users to submit likes on password-protected and group-restricted videos. This vulnerability allows malicious actors to manipulate like counts by submitting requests for videos they should not have access to, thus circumventing the established access controls. Users and administrators are advised to review configurations and apply necessary patches to protect against unauthorized interactions with video content.

Affected Version(s)

AVideo 0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

santhreal
.