Unauthorized Access Vulnerability in WWBN AVideo
CVE-2026-90548

6.9MEDIUM

Key Information:

Vendor

Wwbn

Status
Vendor
CVE Published:
12 September 2026

What is CVE-2026-90548?

The AVideo platform by WWBN contains a vulnerability in the ImageGallery's list.json.php endpoint. This flaw arises from inadequate user permission validation, enabling unauthenticated users to access and retrieve filenames and URLs of password-protected image galleries. Malicious actors can directly interact with the endpoint to expose sensitive gallery files without any authentication, posing significant risks to user data privacy and integrity. It is crucial for administrators and users to take proactive measures to secure their installations against such unauthorized access.

Affected Version(s)

AVideo 0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

santhreal
.