Description
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to require authentication in the plugin/TopMenu/menus.json.php endpoint, allowing unauthenticated attackers to retrieve all menu data. Attackers can send GET requests to the endpoint to read inactive and admin-only menu names that are not displayed in the public navbar.
Published: 2026-09-12
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthenticated Information Disclosure
Action: Patch Now
AI Analysis

Impact

WWBN AVideo's TopMenu plugin exposes a /plugin/TopMenu/menus.json.php endpoint that does not enforce authentication. An unauthenticated attacker can issue a simple GET request to that URL and receive a JSON payload containing all menu items, including inactive and admin‑only entries that are normally hidden from the public interface. This constitutes an information disclosure vulnerability (CWE‑200) that could reveal internal application structure or privileged actions to the attacker.

Affected Systems

All installations of WWBN AVideo that include the TopMenu plugin are affected. The CVE statement does not provide a specific version range, so any release that still ships the unauthenticated endpoint is vulnerable. Administrators should assume the endpoint is exposed until the vendor.

Risk and Exploitability

The flaw carries a CVSS score of 6.9, indicating moderate severity. The EPSS score of less than 1% suggests a low but non‑zero likelihood of exploitation in the wild, and it is not currently listed in the CISA KEV catalog. Attackers can exploit the vulnerability by sending an unauthenticated HTTP GET request to the endpoint from any location that can reach the web server; no special network configuration is required. The path to exploitation is straightforward, and the weakness does not require user interaction or administrative privileges.

Generated by OpenCVE AI on September 15, 2026 at 18:09 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to the latest WWBN AVideo release that includes the TopMenu plugin fix.
  • If the patch cannot be applied immediately, restrict access to the /plugin/TopMenu/menus.json.php URL via web server authentication or firewall rules, ensuring only authorized users can retrieve the menus.
  • If the TopMenu plugin is not required for the site, disable or uninstall it to eliminate the vulnerable endpoint entirely.

Generated by OpenCVE AI on September 15, 2026 at 18:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 12 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Description WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to require authentication in the plugin/TopMenu/menus.json.php endpoint, allowing unauthenticated attackers to retrieve all menu data. Attackers can send GET requests to the endpoint to read inactive and admin-only menu names that are not displayed in the public navbar.
Title WWBN AVideo Unauthenticated Information Disclosure via menus.json.php
First Time appeared Wwbn
Wwbn avideo
Weaknesses CWE-200
CPEs cpe:2.3:a:wwbn:avideo:-:*:*:*:*:*:*:*
Vendors & Products Wwbn
Wwbn avideo
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-19T14:21:55.588Z

Reserved: 2026-09-12T11:12:50.792Z

Link: CVE-2026-90541

cve-icon Vulnrichment

Updated: 2026-09-19T14:18:42.919Z

cve-icon NVD

Status : Deferred

Published: 2026-09-12T13:16:52.220

Modified: 2026-09-19T15:17:07.500

Link: CVE-2026-90541

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T18:15:11Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor