Description
AVideo through 29.0 contains an insecure direct object reference (IDOR) vulnerability in objects/categoryDeleteAssets.json.php. The endpoint validates only the Category::canCreateCategory() capability and a CSRF nonce before passing the attacker-supplied $_REQUEST['id'] to Category::deleteAssets(), which recursively removes {systemRootPath}videos/categories/assets/{id}/. It omits the Category::userCanEditCategory() ownership check enforced by the sibling Category::delete(). On installations where the non-default usersCanCreateNewCategories setting is enabled, an authenticated non-admin user with the canUpload capability can send a POST request with an arbitrary category ID and recursively delete any category's on-disk asset directory (icons/images). Category records and videos are not deleted. As of the advisory publication no patched version was available.
Published: 2026-09-11
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Insecure direct object reference allowing deletion of category asset directories by unauthorized users
Action: Assess Impact
AI Analysis

Impact

AVideo versions through 29.0 contain an IDOR flaw in the objects/categoryDeleteAssets.json.php endpoint, where only a canCreateCategory capability and a CSRF nonce are verified. The endpoint then passes recursively removing the on‑disk asset directory of that category. The ownership check enforced by delete() is omitted, so a non‑admin user who has the canUpload and category‑create permissions, though the database records and video files remain intact.

Affected Systems

Any WWBN AVideo installation up to and including version 29.0 where the non‑default usersCanCreateNewCategories setting is enabled. The flaw affects installations that expose the endpoint to authenticated users possessing the canUpload capability.

Risk and Exploitability

The CVSS score is 5.3, indicating moderate severity. EPSS is not provided and the vulnerability is not listed in KEV. Exploitation requires a legitimate user account with the canUpload and category‑create permissions; an attacker must send a crafted POST request to the vulnerable endpoint. Due to the need for authenticated access, the attack vector is limited to users who have legitimate access but potentially misconfigured permissions.

Generated by OpenCVE AI on September 11, 2026 at 14:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Disable the usersCanCreateNewCategories setting or restrict it to administrators only to remove the ability for non‑admin users to create new categories.
  • Revoke or remove the canUpload capability from all non‑admin users to prevent them from invoking the deleteAssets endpoint.
  • Apply a temporary patch by manually inserting an ownership check (e.g., Category::userCanEditCategory()) before the deletion logic, or disable the objects/categoryDeleteAssets.json.php endpoint until an official vendor fix is released.

Generated by OpenCVE AI on September 11, 2026 at 14:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Description AVideo through 29.0 contains an insecure direct object reference (IDOR) vulnerability in objects/categoryDeleteAssets.json.php. The endpoint validates only the Category::canCreateCategory() capability and a CSRF nonce before passing the attacker-supplied $_REQUEST['id'] to Category::deleteAssets(), which recursively removes {systemRootPath}videos/categories/assets/{id}/. It omits the Category::userCanEditCategory() ownership check enforced by the sibling Category::delete(). On installations where the non-default usersCanCreateNewCategories setting is enabled, an authenticated non-admin user with the canUpload capability can send a POST request with an arbitrary category ID and recursively delete any category's on-disk asset directory (icons/images). Category records and videos are not deleted. As of the advisory publication no patched version was available.
Title AVideo through 29.0 Cross-User Category Asset Deletion via Missing Ownership Check
First Time appeared Wwbn
Wwbn avideo
Weaknesses CWE-639
CPEs cpe:2.3:a:wwbn:avideo:*:*:*:*:*:*:*:*
Vendors & Products Wwbn
Wwbn avideo
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-15T16:16:54.171Z

Reserved: 2026-09-11T10:51:59.215Z

Link: CVE-2026-89257

cve-icon Vulnrichment

Updated: 2026-09-15T16:16:45.907Z

cve-icon NVD

Status : Deferred

Published: 2026-09-11T12:16:56.160

Modified: 2026-09-15T17:17:35.743

Link: CVE-2026-89257

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T17:45:18Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key