Authorization Vulnerability in AVideo by WWBN
CVE-2026-92586
5.3MEDIUM
What is CVE-2026-92586?
AVideo versions up to 29.0 fail to properly check permissions in the set_api_comment function. This issue allows authenticated users to post comments on videos that are protected by passwords or restricted to specific groups. Attackers can exploit this flaw by sending POST requests to the comment API endpoint with any video ID, thus bypassing access controls and potentially spamming content on videos they should not have access to.
Affected Version(s)
AVideo 0
AVideo 0 <= 29.0
