Authorization Bypass in WWBN AVideo Affects Private Playlist Access
CVE-2026-90551

6.9MEDIUM

Key Information:

Vendor

Wwbn

Status
Vendor
CVE Published:
12 September 2026

What is CVE-2026-90551?

The WWBN AVideo product has a vulnerability in the video_from_program API endpoint, where it fails to properly verify the ownership of playlists. This oversight permits unauthenticated attackers to access private playlist information, thus allowing them to enumerate playlist names, retrieve owner details, and view video titles, including those protected by passwords. This lack of authorization can lead to significant privacy breaches within the platform.

Affected Version(s)

AVideo 0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

santhreal
.