Description
WWBN AVideo contains an authentication failure vulnerability where the video_id_hash credential is a non-expiring, non-revocable bearer token that grants full administrator session access to the video owner's account. Attackers who obtain a video_id_hash can replay it indefinitely to authenticate as the video owner with full privileges, and the credential remains valid even after the owner changes their password.
Published: 2026-09-03
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

WWBN AVideo includes a flaw where the video_id_hash credential behaves as a non‑expiring, non‑revocable bearer token. An attacker who obtains a valid video_id_hash can replay it indefinitely to authenticate as the video owner, gaining complete administrative control over the account. The credential remains valid even after the owner changes their password, enabling prolonged compromise. This constitutes an authentication bypass that results in full privilege escalation.

Affected Systems

The vulnerability affects the WWBN AVideo platform. No specific version information is supplied, so all deployments of AVideo are considered potentially vulnerable until a patch is applied.

Risk and Exploitability

The CVSS score is 9.3, indicating critical severity. EPSS data is not available, but the lack of a revocation mechanism suggests that exploitation can occur as long as the token is present. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote, accessed through the public web interface of AVideo. An attacker can obtain a video_id_hash by exploiting other weaknesses or through social engineering, then use it to authenticate as any owner whose token remains active.

Generated by OpenCVE AI on September 3, 2026 at 12:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest AVideo release that removes or secures the non‑expiring video_id_hash functionality
  • Revoke or regenerate all existing video_id_hash tokens for users whose credentials may have been compromised
  • Configure AVideo, if possible, to enforce expiration or revocation of bearer tokens and disable legacy authentication modes
  • Monitor logs for abnormal authentication attempts using video_id_hash tokens and review user activity for signs of compromise

Generated by OpenCVE AI on September 3, 2026 at 12:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Description WWBN AVideo contains an authentication failure vulnerability where the video_id_hash credential is a non-expiring, non-revocable bearer token that grants full administrator session access to the video owner's account. Attackers who obtain a video_id_hash can replay it indefinitely to authenticate as the video owner with full privileges, and the credential remains valid even after the owner changes their password.
Title WWBN AVideo Authentication Bypass via Non-Expiring video_id_hash
First Time appeared Wwbn
Wwbn avideo
Weaknesses CWE-269
CPEs cpe:2.3:a:wwbn:avideo:*:*:*:*:*:*:*:*
Vendors & Products Wwbn
Wwbn avideo
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-03T11:22:08.455Z

Reserved: 2026-09-03T11:04:41.806Z

Link: CVE-2026-85154

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-03T13:06:22.067

Modified: 2026-09-03T13:06:22.067

Link: CVE-2026-85154

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T13:00:04Z

Weaknesses
  • CWE-269

    Improper Privilege Management