Authorization Flaw in WWBN AVideo Allows Access to Sensitive Video Information
CVE-2026-90549
6.9MEDIUM
What is CVE-2026-90549?
The AVideo platform contains a vulnerability that allows unauthorized users to access sensitive information associated with password-protected videos. This issue arises from inadequate authorization mechanisms in the videosAndroid.json.php endpoint, which permits unauthenticated requests to retrieve sensitive video metadata, including user email addresses, filenames, and identifiers. Consequently, malicious actors can exploit this flaw to gain unauthorized insight into private video content and user details.
Affected Version(s)
AVideo 0
