Description
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate video access permissions in the commentAddNew.json.php endpoint, allowing authenticated users to post comments on password-protected and group-restricted videos. Attackers can submit POST requests with a valid session to add comments to videos they cannot watch, bypassing password and group access controls.
Published: 2026-09-12
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Missing Authorization
Action: Patch Now
AI Analysis

Impact

The vulnerability is located in the commentAddNew.json.php endpoint of WWBN AVideo and is a CWE-862 Missing Authorization flaw. It occurs because the code does not validate permission to view a video before allowing a comment to be posted. As a result, an authenticated user can send POST requests with a valid session token to add comments on videos that are protected by passwords, granting unauthorized social‑engineering or spam activity on content that the user should not have visibility of.

Affected Systems

The affected product is WWBN AVideo. The commit between c3edcc274c389816d434acadac07ee78eaf330c1 and its successors exposes the flaw. No specific released versions are listed, so any installation that has not incorporated this commit remains vulnerable.

Risk and Exploitability

The CVSS score of 5.3 indicates a medium severity vulnerability. The EPSS score is below 1 %, suggesting a low probability of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an authenticated session, so the attacker must either steal or hijack a user’s session token or convince a user to expose it. Once authenticated, the attacker can add comments to restricted videos, possibly bypassing privacy controls and facilitating social‑engineering or defacement. The attack vector is limited to authenticated POST requests to the commentAddNew.json.php endpoint.

Generated by OpenCVE AI on September 15, 2026 at 18:08 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest AVideo release that includes the missing authorization fix for the commentAddNew.json.php endpoint.
  • the code or configuration so that a comment can be accepted only when the user has viewing rights for the target video.
  • Audit the comment database for protected videos and remove any comments added by users who should not have had viewing access.

Generated by OpenCVE AI on September 15, 2026 at 18:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 12 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Description WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate video access permissions in the commentAddNew.json.php endpoint, allowing authenticated users to post comments on password-protected and group-restricted videos. Attackers can submit POST requests with a valid session to add comments to videos they cannot watch, bypassing password and group access controls.
Title WWBN AVideo Missing Authorization via commentAddNew.json.php
First Time appeared Wwbn
Wwbn avideo
Weaknesses CWE-862
CPEs cpe:2.3:a:wwbn:avideo:-:*:*:*:*:*:*:*
Vendors & Products Wwbn
Wwbn avideo
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-14T16:02:38.607Z

Reserved: 2026-09-12T11:13:17.618Z

Link: CVE-2026-90545

cve-icon Vulnrichment

Updated: 2026-09-14T16:02:34.193Z

cve-icon NVD

Status : Deferred

Published: 2026-09-12T13:16:52.777

Modified: 2026-09-14T21:07:11.883

Link: CVE-2026-90545

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T18:15:11Z

Weaknesses