Authentication Bypass Vulnerability in AVideo by WorldWide Broadcast Network
CVE-2026-92913
9.1CRITICAL
What is CVE-2026-92913?
The AVideo platform utilizes a weak pseudo-random number generator to create account activation and login pairing codes, leading to serious security concerns. The generation of these codes through uniqid() limits the potential combinations, making it susceptible to brute-force attacks. Unauthenticated attackers can exploit this vulnerability to derive valid codes, compromising user emails and gaining access to credentials that expire after one year. Thus, the affected product allows for an unverified user to take control of an account, significantly threatening the integrity of user data. No patched version of this product has been released as of now.
Affected Version(s)
AVideo 0
