Description
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate video access permissions in the like.json.php endpoint, allowing logged-in users to record likes on password-protected and group-restricted videos. Attackers can submit like requests for videos they cannot watch to increment like counters and bypass access controls.
Published: 2026-09-12
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Access Control Bypass (unauthorized liking of restricted videos)
Action: Apply Patch
AI Analysis

Impact

WWBN AVideo contains an access‑control flaw that allows an authenticated user to submit like requests via the like.json.php endpoint without first verifying that the user has permission to view the target video. The flaw is identified as CWE-862. As a result, users can increment the like counter for password‑protected or group‑restricted videos, potentially manipulating popularity metrics and indirectly confirming the existence of protected content.

Affected Systems

The vulnerability affects all installations of WWBN AVideo for which the like.json.php endpoint does not enforce permission checks. No specific version or build information to any instance that has not applied the corrections documented in the advisory references.

Risk and Exploitability

The CVE has a medium severity range, and the EPSS score of < 1 % indicates a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Likely attackers are authenticated web users capable of sending HTTP POST requests to like.json.php; no additional privileges are required beyond an attacker to increment likes on videos they cannot access, thereby bypassing intended access controls.

Generated by OpenCVE AI on September 15, 2026 at 03:16 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Acquire and apply the vendor‑supplied patch referenced in the GitHub advisory to restore permission checks on like.json.php.
  • If applying the patch is currently infeasible, remove or disable the like.json.php endpoint to prevent unsolicited like requests for protected content.
  • As an interim control, implement server‑side validation to confirm that a user has permission to view a video before recording a like request.

Generated by OpenCVE AI on September 15, 2026 at 03:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 12 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Description WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate video access permissions in the like.json.php endpoint, allowing logged-in users to record likes on password-protected and group-restricted videos. Attackers can submit like requests for videos they cannot watch to increment like counters and bypass access controls.
Title WWBN AVideo Missing Authorization via like.json.php
First Time appeared Wwbn
Wwbn avideo
Weaknesses CWE-862
CPEs cpe:2.3:a:wwbn:avideo:-:*:*:*:*:*:*:*
Vendors & Products Wwbn
Wwbn avideo
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-21T16:14:04.010Z

Reserved: 2026-09-12T11:13:17.618Z

Link: CVE-2026-90546

cve-icon Vulnrichment

Updated: 2026-09-21T16:13:59.987Z

cve-icon NVD

Status : Deferred

Published: 2026-09-12T13:16:52.913

Modified: 2026-09-21T17:19:15.503

Link: CVE-2026-90546

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T03:30:14Z

Weaknesses