Description
WWBN AVideo through commit e01e41ecc (no patched version available) exposes get_api_preauthorize in plugin/API/API.php as a second, undocumented login path. Unlike get_api_signIn, which enforces a rate limit of 10 attempts per 5 minutes via checkRateLimit(), get_api_preauthorize performs the same credential check with no throttling for any client, allowing unlimited remote password guessing against arbitrary accounts, including admin. The endpoint also acts as a credential oracle: it returns the message "Invalid credentials" for both correct and incorrect passwords, while the users_id field in the response body discloses the authenticated identity (users_id:1 on success, users_id:0 on failure), and a correct password establishes a session cookie that remains usable for authenticated API requests. Together these issues permit unauthenticated brute-force account takeover.
Published: 2026-09-08
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Account Takeover via Unrestricted Brute Force
Action: Apply Mitigation
AI Analysis

Impact

The vulnerability in WWBN AVideo allows an attacker to perform unlimited password guesses against any user account through the undocumented get_api_preauthorize endpoint. The endpoint omits rate limiting, checks credentials the same way as the official sign‑in route, and returns a generic "Invalid credentials" message for both correct and incorrect passwords. However, the response includes the authenticated identity via a users_id field (users_id:1 for success, users_id:0 for failure) and, on a successful credential match, establishes a session cookie usable for subsequent authenticated API calls. This combination permits passive credential enumeration followed by active account takeover without any special privileges or local access.

Affected Systems

Any installation of the WWBN AVideo plugin where plugin/API/API.php exposes the get_api_preauthorize endpoint, including the commit e01e41ecc. No patched version is currently available, so all current releases remain vulnerable.

Risk and Exploitability

With a CVSS score of 9.1, the vulnerability is classified as critical. No EPSS data is available, and the vulnerability is not listed in CISA's KEV catalog, but the absence of throttling and the ability to gain legitimate session cookies from successful guesses make exploitation highly feasible for remote attackers. The attack vector is remote and does not require any privileged credentials; an adversary only needs network access to the API endpoint.

Generated by OpenCVE AI on September 8, 2026 at 16:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Restrict access to the get_api_preauthorize endpoint using firewall or reverse proxy rules so that only trusted IP addresses can reach it.
  • Implement custom rate limiting or brute‑force protection on the authentication routes, or replace the endpoint with a hardened version that enforces limits.
  • If the endpoint is unnecessary, consider disabling or removing it entirely, or patch the code to add proper throttling and enforce the documented sign‑in flow.

Generated by OpenCVE AI on September 8, 2026 at 16:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description WWBN AVideo through commit e01e41ecc (no patched version available) exposes get_api_preauthorize in plugin/API/API.php as a second, undocumented login path. Unlike get_api_signIn, which enforces a rate limit of 10 attempts per 5 minutes via checkRateLimit(), get_api_preauthorize performs the same credential check with no throttling for any client, allowing unlimited remote password guessing against arbitrary accounts, including admin. The endpoint also acts as a credential oracle: it returns the message "Invalid credentials" for both correct and incorrect passwords, while the users_id field in the response body discloses the authenticated identity (users_id:1 on success, users_id:0 on failure), and a correct password establishes a session cookie that remains usable for authenticated API requests. Together these issues permit unauthenticated brute-force account takeover.
Title WWBN AVideo Unrestricted Authentication Attempts via get_api_preauthorize
First Time appeared Wwbn
Wwbn avideo
Weaknesses CWE-307
CPEs cpe:2.3:a:wwbn:avideo:*:*:*:*:*:*:*:*
Vendors & Products Wwbn
Wwbn avideo
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'}

cvssV4_0

{'score': 9.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-10T15:02:34.360Z

Reserved: 2026-09-08T11:31:09.013Z

Link: CVE-2026-86729

cve-icon Vulnrichment

Updated: 2026-09-10T14:18:56.854Z

cve-icon NVD

Status : Deferred

Published: 2026-09-08T16:18:34.523

Modified: 2026-09-10T16:18:03.893

Link: CVE-2026-86729

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T17:00:02Z

Weaknesses
  • CWE-307

    Improper Restriction of Excessive Authentication Attempts