Authentication Bypass Vulnerability in AVideo by WorldWide Broadcast Network
CVE-2026-92913

9.1CRITICAL

Key Information:

Vendor

Wwbn

Status
Vendor
CVE Published:
17 September 2026

What is CVE-2026-92913?

The AVideo platform utilizes a weak pseudo-random number generator to create account activation and login pairing codes, leading to serious security concerns. The generation of these codes through uniqid() limits the potential combinations, making it susceptible to brute-force attacks. Unauthenticated attackers can exploit this vulnerability to derive valid codes, compromising user emails and gaining access to credentials that expire after one year. Thus, the affected product allows for an unverified user to take control of an account, significantly threatening the integrity of user data. No patched version of this product has been released as of now.

Affected Version(s)

AVideo 0

References

CVSS V4

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

santhreal
.