Description
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in playlistsFromUser.json.php that allows unauthenticated attackers to read private playlists by requesting another user's identifier. Attackers can retrieve Favorite and Watch Later playlists belonging to other users due to improper cache keying that conflates requests across different user contexts.
Published: 2026-09-12
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Information Disclosure
Action: Patch Now
AI Analysis

Impact

WWBN AVideo contains a missing‑authorization flaw in the playlistsFromUser.json.php endpoint that permits any unauthenticated user to download the private Favorite and Watch Later playlists of any account by supplying that account’s identifier. The vulnerability is a CWE‑200 confidentiality issue that arises from the lack of requester validation and from improper cache keying that merges requests across distinct user contexts, thereby leaking confidential user data.

Affected Systems

All installations of WWBN AVideo that include the code from commit c3edcc274c389816d434acadac07ee78eaf330c1 are affected. Administrators should verify that their deployment is at least this commit or newer, as only releases that incorporate the missing‑authorization fix in playlistsFromUser.json.php address the issue.

Risk and Exploitability

The CVSS score of 6.9 classifies the vulnerability as moderately severe, while the EPSS score of less than 1% indicates a low but non‑zero chance of exploitation. It is not listed in CISA’s KEV catalog. The likely attack vector is a remote, unauthenticated HTTP request to the publicly reachable playlistsFromUser.json.php endpoint. Based on the description, it is inferred that an attacker sends a crafted request such as /playlistsFromUser.json.php?userId=<target>, bypassing any authentication and retrieving the target’s private playlists.

Generated by OpenCVE AI on September 15, 2026 at 19:34 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update WWBN AVideo to the latest release that includes the fixed authorization checks and proper cache key separation in playlistsFromUser.json.php.
  • If updating immediately is not feasible, configure the web server or reverse proxy to require authentication before accessing playlistsFromUser.json.php, effectively blocking unauthenticated requests.
  • Deploy network‑level controls, such as a WAF rule or IP filtering, to restrict access to the playlistsFromUser.json.php endpoint from untrusted networks.
  • Disable caching for playlistsFromUser.json.php or enforce distinct cache keys per user to prevent cross‑user data leakage.
  • Monitor access logs for suspicious requests to the endpoint and verify that the authorization checks are functioning as intended.

Generated by OpenCVE AI on September 15, 2026 at 19:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 12 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Description WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in playlistsFromUser.json.php that allows unauthenticated attackers to read private playlists by requesting another user's identifier. Attackers can retrieve Favorite and Watch Later playlists belonging to other users due to improper cache keying that conflates requests across different user contexts.
Title WWBN AVideo Missing Authorization via playlistsFromUser.json.php
First Time appeared Wwbn
Wwbn avideo
Weaknesses CWE-200
CPEs cpe:2.3:a:wwbn:avideo:-:*:*:*:*:*:*:*
Vendors & Products Wwbn
Wwbn avideo
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-14T18:28:28.938Z

Reserved: 2026-09-12T11:12:50.791Z

Link: CVE-2026-90538

cve-icon Vulnrichment

Updated: 2026-09-14T18:28:13.047Z

cve-icon NVD

Status : Deferred

Published: 2026-09-12T13:16:51.807

Modified: 2026-09-14T21:07:11.883

Link: CVE-2026-90538

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T19:45:07Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor