Description
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authentication vulnerability in the plugin/TopMenu/menuItems.json.php endpoint that allows unauthenticated attackers to read inactive admin menu items by submitting a POST request with a menuId parameter. Attackers can retrieve hidden menu item URLs including embedded admin-tool secret query parameters not exposed in the public navbar.
Published: 2026-09-12
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information disclosure of hidden administrative URLs
Action: Apply Patch
AI Analysis

Impact

A missing authentication check in the plugin/TopMenu/menuItems.json.php endpoint of WWBN AVideo allows an attacker to send an unauthenticated POST request containing a menuId parameter. The response includes inactive admin menu items that are normally hidden from the public navigation bar. These items expose secret administrative URLs with query parameters that an attacker can use without needing further privileges.

Affected Systems

The vulnerability affects the WWBN as c3edcc274c389816d434acadac07ee78eaf330c1. Earlier commits are not explicitly listed but may also be impacted if the same endpoint continues to lack authentication checks. No specific version range is supplied; all affected installations that expose the vulnerable endpoint are at risk.

Risk and Exploitability

The CVSS base score is 6.9, indicating moderate severity. The EPSS score is less than 1%, showing a very low likelihood of exploitation by current actors. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Attackers can exploit this weakness remotely by reaching the AVideo server over the network and submitting the malformed POST request. Because no authentication is required, the vulnerability can be used by any adversary who can reach the endpoint.

Generated by OpenCVE AI on September 15, 2026 at 18:11 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest AVideo patch that enforces authentication on the menuItems.json.php endpoint.
  • Configure the application to restrict access to the TopMenu plugin endpoint so that only authenticated administrators can call it.
  • Monitor logs for unauthenticated POST attempts to plugin/TopMenu/menuItems.json.php and investigate suspicious activity.

Generated by OpenCVE AI on September 15, 2026 at 18:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 12 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Description WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authentication vulnerability in the plugin/TopMenu/menuItems.json.php endpoint that allows unauthenticated attackers to read inactive admin menu items by submitting a POST request with a menuId parameter. Attackers can retrieve hidden menu item URLs including embedded admin-tool secret query parameters not exposed in the public navbar.
Title WWBN AVideo Missing Authentication via menuItems.json.php
First Time appeared Wwbn
Wwbn avideo
Weaknesses CWE-200
CPEs cpe:2.3:a:wwbn:avideo:-:*:*:*:*:*:*:*
Vendors & Products Wwbn
Wwbn avideo
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-14T18:16:48.054Z

Reserved: 2026-09-12T11:12:50.791Z

Link: CVE-2026-90539

cve-icon Vulnrichment

Updated: 2026-09-14T17:06:18.896Z

cve-icon NVD

Status : Deferred

Published: 2026-09-12T13:16:51.943

Modified: 2026-09-14T21:07:11.883

Link: CVE-2026-90539

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T18:15:11Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor