Authorization Bypass in AVideo Allows Unrestricted Voting
CVE-2026-92585
5.3MEDIUM
What is CVE-2026-92585?
AVideo, up to version 29.0, contains a flaw in its API that bypasses permission validation for voting on videos. This issue allows authenticated users to cast votes on videos that are password-protected or group-restricted by leveraging the set.json.php endpoint. Attackers can manipulate the APIName parameters to increment vote counters on inaccessible videos, potentially skewing engagement metrics.
Affected Version(s)
AVideo 0
AVideo 0 <= 29.0
