Authorization Bypass in WWBN AVideo Affects Private Playlist Access
CVE-2026-90551
6.9MEDIUM
What is CVE-2026-90551?
The WWBN AVideo product has a vulnerability in the video_from_program API endpoint, where it fails to properly verify the ownership of playlists. This oversight permits unauthenticated attackers to access private playlist information, thus allowing them to enumerate playlist names, retrieve owner details, and view video titles, including those protected by passwords. This lack of authorization can lead to significant privacy breaches within the platform.
Affected Version(s)
AVideo 0
