Unauthorized Access Vulnerability in WWBN AVideo
CVE-2026-90548
6.9MEDIUM
What is CVE-2026-90548?
The AVideo platform by WWBN contains a vulnerability in the ImageGallery's list.json.php endpoint. This flaw arises from inadequate user permission validation, enabling unauthenticated users to access and retrieve filenames and URLs of password-protected image galleries. Malicious actors can directly interact with the endpoint to expose sensitive gallery files without any authentication, posing significant risks to user data privacy and integrity. It is crucial for administrators and users to take proactive measures to secure their installations against such unauthorized access.
Affected Version(s)
AVideo 0
