Authorization Flaw in WWBN AVideo Results in Inaccessible Playlist Metadata
CVE-2026-90552

5.3MEDIUM

Key Information:

Vendor

Wwbn

Status
Vendor
CVE Published:
12 September 2026

What is CVE-2026-90552?

An authorization flaw exists in the WWBN AVideo platform, where certain API endpoints fail to validate the ownership of playlists. Specifically, the 'Playlists_schedules/list.json.php' and 'Live/calendar.json.php' endpoints can be accessed by both authenticated and unauthenticated users. Attackers can exploit this oversight to retrieve sensitive metadata related to private playlists including schedule names, descriptions, timestamps, and identifiers, without proper ownership checks in place. This vulnerability poses a significant risk as it allows potential information leakage to users who should not have access to this private information.

Affected Version(s)

AVideo 0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

santhreal
.