Authorization Flaw in WWBN AVideo Allows Access to Sensitive Video Information
CVE-2026-90549

6.9MEDIUM

Key Information:

Vendor

Wwbn

Status
Vendor
CVE Published:
12 September 2026

What is CVE-2026-90549?

The AVideo platform contains a vulnerability that allows unauthorized users to access sensitive information associated with password-protected videos. This issue arises from inadequate authorization mechanisms in the videosAndroid.json.php endpoint, which permits unauthenticated requests to retrieve sensitive video metadata, including user email addresses, filenames, and identifiers. Consequently, malicious actors can exploit this flaw to gain unauthorized insight into private video content and user details.

Affected Version(s)

AVideo 0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

santhreal
.