Authorization Flaw in WWBN AVideo Results in Inaccessible Playlist Metadata
CVE-2026-90552
5.3MEDIUM
What is CVE-2026-90552?
An authorization flaw exists in the WWBN AVideo platform, where certain API endpoints fail to validate the ownership of playlists. Specifically, the 'Playlists_schedules/list.json.php' and 'Live/calendar.json.php' endpoints can be accessed by both authenticated and unauthenticated users. Attackers can exploit this oversight to retrieve sensitive metadata related to private playlists including schedule names, descriptions, timestamps, and identifiers, without proper ownership checks in place. This vulnerability poses a significant risk as it allows potential information leakage to users who should not have access to this private information.
Affected Version(s)
AVideo 0
