Description
WWBN AVideo fails to properly validate access controls on the public channel page, allowing unauthenticated visitors to view unlisted and group-restricted videos through hardcoded visibility flags and an undefined property. Attackers can access the channel endpoint to retrieve sensitive video content that should be hidden, including full URLs to unlisted videos and thumbnails of member-only content, regardless of the operator's hidePrivateVideos setting.
Published: 2026-09-03
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

WWBN AVideo contains a broken access control flaw that allows any visitor to the public channel page to view private, unlisted, and group‑restricted video content. The flaw arises from a hardcoded visibility flag and an undefined property that bypasses the operator’s hidePrivateVideos setting. The consequence is the accidental exposure of full video URLs and thumbnails, leading to confidentiality compromise of content that should otherwise remain hidden.

Affected Systems

The vulnerability affects the WWBN:AVideo product. No specific patch version or affected release is listed in the CVE data, so all deployments of this software are potentially impacted until a fix is applied.

Risk and Exploitability

The CVSS score is 6.9, indicating a moderate severity. The EPSS score is not available and the vulnerability is not listed in CISA KEV, suggesting no known active exploitation campaigns. Attackers can exploit the flaw by simply navigating to the affected channel endpoint—no authentication is required. Once reached, they can retrieve sensitive video URLs and thumbnails that are intended to be private.

Generated by OpenCVE AI on September 3, 2026 at 12:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor’s latest patch or upgrade AVideo to the fixed release
  • If a patch is unavailable, disable anonymous access to the public channel page or enforce authentication before view access
  • Monitor logs for unauthorized video access and block suspicious IP addresses

Generated by OpenCVE AI on September 3, 2026 at 12:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Description WWBN AVideo fails to properly validate access controls on the public channel page, allowing unauthenticated visitors to view unlisted and group-restricted videos through hardcoded visibility flags and an undefined property. Attackers can access the channel endpoint to retrieve sensitive video content that should be hidden, including full URLs to unlisted videos and thumbnails of member-only content, regardless of the operator's hidePrivateVideos setting.
Title WWBN AVideo Broken Access Control via Channel Page
First Time appeared Wwbn
Wwbn avideo
Weaknesses CWE-200
CPEs cpe:2.3:a:wwbn:avideo:*:*:*:*:*:*:*:*
Vendors & Products Wwbn
Wwbn avideo
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-03T14:30:29.709Z

Reserved: 2026-09-03T11:04:41.806Z

Link: CVE-2026-85156

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-03T13:06:22.360

Modified: 2026-09-03T13:06:22.360

Link: CVE-2026-85156

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T13:45:04Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor