Description
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in plugin/Scheduler/sendEmail.json.php that allows unauthenticated attackers to access scheduler email jobs by providing a site-wide daily token. Attackers can enumerate scheduler jobs, read private live titles and email addresses, and trigger email sending by supplying any valid daily token obtained from Live pages.
Published: 2026-09-12
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Access to Scheduler Emails
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a missing authorization check in AVideo’s Scheduler plugin. An attacker can supply a site‑wide daily token to the sendEmail.json.php endpoint and retrieve details of scheduled email jobs, view private live titles and recipient addresses, and trigger emails to be sent. This exposes confidential information and allows unsolicited email dispatches. The weakness aligns with CWE‑862, representing an authorization flaw.

Affected Systems

WWBN AVideo’s Scheduler plugin, all releases before434acadac07ee78eaf330c1. The vulnerability is present in every affected release that has not applied this commit, regardless of exact version numbers. The product is identified as WWBN:AVideo.

Risk and Exploitability

The CVSS score of 8.8 indicates a high severity. The EPSS score of <1% points to a very low, yet non‑zero, probability of exploitation, and the flaw is not listed in CISA KEV. Attackers can obtain the required token by viewing Live pages, and then send HTTP requests to the open endpoint, so exploitation is feasible without special privileges.

Generated by OpenCVE AI on September 15, 2026 at 18:50 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest official patch that includes commit c3edcc274c389816d434acadac07ee78eaf330c1 to fix the missing authorization check.
  • Configure the web server or reverse proxy to restrict access to the sendEmail.json.php endpoint to trusted IP ranges or authenticated users, for example by using firewall rules or web‑application configuration.
  • Monitor the email system logs for abnormal sending patterns that could indicate unauthorized use of the scheduler endpoint.

Generated by OpenCVE AI on September 15, 2026 at 18:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 12 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Description WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in plugin/Scheduler/sendEmail.json.php that allows unauthenticated attackers to access scheduler email jobs by providing a site-wide daily token. Attackers can enumerate scheduler jobs, read private live titles and email addresses, and trigger email sending by supplying any valid daily token obtained from Live pages.
Title WWBN AVideo Scheduler sendEmail Missing Authorization via Token
First Time appeared Wwbn
Wwbn avideo
Weaknesses CWE-862
CPEs cpe:2.3:a:wwbn:avideo:-:*:*:*:*:*:*:*
Vendors & Products Wwbn
Wwbn avideo
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N'}

cvssV4_0

{'score': 8.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-15T17:00:31.027Z

Reserved: 2026-09-12T11:12:50.791Z

Link: CVE-2026-90537

cve-icon Vulnrichment

Updated: 2026-09-15T17:00:25.782Z

cve-icon NVD

Status : Deferred

Published: 2026-09-12T13:16:51.667

Modified: 2026-09-15T17:17:37.923

Link: CVE-2026-90537

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T19:00:15Z

Weaknesses