Broken Access Control in AVideo API Exposes Sensitive User Data
CVE-2026-92577

8.7HIGH

Key Information:

Vendor

Wwbn

Status
Vendor
CVE Published:
16 September 2026

What is CVE-2026-92577?

A vulnerability exists in AVideo versions up to 29.0 within the API's get_api_video endpoint. This flaw in the clean_title branch allows unauthorized users to bypass group restrictions, leading to exposure of sensitive user information. Attackers can exploit this vulnerability by querying videos using their public slugs, thereby accessing private data such as email addresses, phone numbers, physical addresses, birth dates, and administrator status of users. This security issue highlights the critical need for robust access control mechanisms to safeguard user information.

Affected Version(s)

AVideo 0 <= 29.0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

rajivraj
.