WWBN AVideo contains a broken access control vulnerability in videoViewsInfo endpoints that returns complete user records including password hashes, recovery tokens, and live session identifiers to unauthenticated callers when a hash parameter is provided. Attackers can use the disclosed session identifier to hijack viewer sessions, including administrator accounts, and obtain sensitive personal data for all video viewers.
Metrics
Affected Vendors & Products
References
History
Tue, 08 Sep 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 05 Sep 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | WWBN AVideo contains a broken access control vulnerability in videoViewsInfo endpoints that returns complete user records including password hashes, recovery tokens, and live session identifiers to unauthenticated callers when a hash parameter is provided. Attackers can use the disclosed session identifier to hijack viewer sessions, including administrator accounts, and obtain sensitive personal data for all video viewers. | |
| Title | WWBN AVideo Broken Access Control via videoViewsInfo hash Parameter | |
| First Time appeared |
Wwbn
Wwbn avideo |
|
| Weaknesses | CWE-200 | |
| CPEs | cpe:2.3:a:wwbn:avideo:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Wwbn
Wwbn avideo |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-09-05T12:09:05.428Z
Updated: 2026-09-08T18:16:30.930Z
Reserved: 2026-09-05T11:51:31.101Z
Link: CVE-2026-86190
Updated: 2026-09-08T18:16:25.463Z
Status : Deferred
Published: 2026-09-05T13:18:14.150
Modified: 2026-09-08T20:05:53.177
Link: CVE-2026-86190
No data.