Unauthorized Access Flaw in WWBN AVideo Media Session Endpoint
CVE-2026-90550
6.9MEDIUM
What is CVE-2026-90550?
The AVideo platform fails to adequately verify user authorization at the mediaSession.json.php endpoint, allowing unauthorized attackers to exploit this weakness. They can send requests containing a video ID parameter to retrieve sensitive information, including titles of password-protected videos and the email addresses of owners, all without the need for authentication. This issue poses a significant risk to user privacy and data integrity within the AVideo service.
Affected Version(s)
AVideo 0
