Description
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate video access permissions in the videoAddViewCount.json.php endpoint before updating view statistics. Authenticated attackers can increment view counts and watch-time on videos they cannot access by submitting requests with arbitrary video IDs.
Published: 2026-09-12
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: View Count Tampering
Action: Immediate Patch
AI Analysis

Impact

The vulnerability in the WWBN AVideo platform occurs at the videoAddViewCount.json.php endpoint, where the system updates view metrics without first verifying that the authenticated user has permission to access the referenced video. Because the request body or query can supply an arbitrary video identifier, an attacker can manipulate the view count and watch‑time statistics for videos they are not allowed to view. This flaw is an authorization bypass (CWE‑862) and does not provide code execution, remote code compromise, or direct data disclosure, but it does undermine the integrity of usage analytics.

Affected Systems

The affected product is WWBN AVideo. The flaw exists in the code base at commit c3edcc274c389816d434acadac07ee78eaf330c1 and is present in any release that has not yet integrated the corrective change referenced by the vendor’s security advisory. No specific version range is listed, so all affected releases before the fix should be considered vulnerable.

Risk and Exploitability

The CVSS score of 5.3 indicates medium severity. The EPSS score of < 1% suggests a low likelihood of exploitation in the wild. The vulnerability is not listed in CISA KEV. An attacker must already be authenticated, and can repeatedly trigger the endpoint with disallowed video identifiers. The principal risk is the integrity of view‑count and watch‑time metrics; the overall threat level remains low due to the limited exploitability and requirement for authentication.

Generated by OpenCVE AI on September 15, 2026 at 18:08 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the AVideo installation to a version that includes the vendor‑issued fix for the videoAddViewCount.json.php endpoint, as detailed in the official advisory.
  • If a patch is not yet available, modify the endpoint implementation to perform an explicit access‑control rights for the supplied video ID before updating any counters.
  • Ensure the endpoint is accessible only to authenticated users; consider enforcing additional controls such as API key validation or restricting requests to trusted IP ranges to further reduce the attack surface.

Generated by OpenCVE AI on September 15, 2026 at 18:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 12 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Description WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate video access permissions in the videoAddViewCount.json.php endpoint before updating view statistics. Authenticated attackers can increment view counts and watch-time on videos they cannot access by submitting requests with arbitrary video IDs.
Title WWBN AVideo Missing Authorization via videoAddViewCount.json.php
First Time appeared Wwbn
Wwbn avideo
Weaknesses CWE-862
CPEs cpe:2.3:a:wwbn:avideo:-:*:*:*:*:*:*:*
Vendors & Products Wwbn
Wwbn avideo
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-14T18:16:35.262Z

Reserved: 2026-09-12T11:13:17.618Z

Link: CVE-2026-90544

cve-icon Vulnrichment

Updated: 2026-09-14T16:14:41.029Z

cve-icon NVD

Status : Deferred

Published: 2026-09-12T13:16:52.640

Modified: 2026-09-14T21:07:11.883

Link: CVE-2026-90544

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T18:15:11Z

Weaknesses