Description
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to authorize access to the adsInfo API endpoint, allowing unauthenticated attackers to retrieve password-protected video owner identifiers. Attackers can call the adsInfo API with a videos_id parameter to obtain the owner's user ID and personalized ad creative URLs without authentication or permission checks.
Published: 2026-09-12
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Assess Impact
AI Analysis

Impact

WWBN AVideo fails to enforce authorization on its adsInfo API endpoint, allowing anyone with network access to query the endpoint with a videos_id parameter and obtain the video owner's user ID and associated advertisement URLs. This missing authorization results in the disclosure of otherwise protected identifiers and privacy‑related data, which the identified weakness (CWE-200) demonstrates is an information exposure vulnerability.

Affected Systems

The flaw exists in the WWBN AVideo platform. All releases prior to the commit c3edcc274c389816d434acadac07ee78eaf330c1 are affected. Installations of the open‑source platform from the WWBN vendor community that have not incorporatedBN AVideo in the vendor catalogue.

Risk and Exploitability

The CVSS base score of 6.9 indicates moderate impact. The EPSS score of <1% suggests a very low probability of exploitation, and the vulnerability has not been recorded in the CISA KEV catalog. Attackers can trigger endpoint over the network; once reached, the service returns the user ID and ad URLs without any authentication. The lack of authorization makes the data available to unauthenticated actors, thereby compromising confidentiality of user identifiers.

Generated by OpenCVE AI on September 15, 2026 at 19:13 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Verify if a newer AVideo release includes the fix, and deploy it if available.
  • Restrict network access to the adsInfo API endpoint by configuring firewall rules, API gateway authentication, or network segmentation to ensure only trusted hosts or authenticated clients can call it.
  • Enable comprehensive logging for the adsInfo endpoint and set up alerts to detect anomalous or unauthenticated requests.

Generated by OpenCVE AI on September 15, 2026 at 19:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 12 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Description WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to authorize access to the adsInfo API endpoint, allowing unauthenticated attackers to retrieve password-protected video owner identifiers. Attackers can call the adsInfo API with a videos_id parameter to obtain the owner's user ID and personalized ad creative URLs without authentication or permission checks.
Title WWBN AVideo Missing Authorization via adsInfo API Endpoint
First Time appeared Wwbn
Wwbn avideo
Weaknesses CWE-200
CPEs cpe:2.3:a:wwbn:avideo:-:*:*:*:*:*:*:*
Vendors & Products Wwbn
Wwbn avideo
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-21T16:13:24.159Z

Reserved: 2026-09-12T11:12:50.791Z

Link: CVE-2026-90536

cve-icon Vulnrichment

Updated: 2026-09-21T16:13:20.063Z

cve-icon NVD

Status : Deferred

Published: 2026-09-12T13:16:51.523

Modified: 2026-09-21T17:19:15.367

Link: CVE-2026-90536

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T19:15:16Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor