Description
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate user permissions in the ImageGallery list.json.php endpoint, allowing unauthenticated access to list gallery files. Attackers can retrieve filenames and URLs of password-protected image galleries by directly accessing the endpoint, then fetch the exposed files without authentication.
Published: 2026-09-12
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Confidentiality breach via unauthorized file disclosure
Action: Immediate Patch
AI Analysis

Impact

The vulnerability resides in WWBN AVideo’s ImageGallery list.json.php endpoint, where the application fails to validate user permissions, enabling an unauthenticated user to read the list of filenames and URLs for galleries. This is an instance of CWE‑200 (Information Exposure) and results in a confidentiality impact, exposing the location of private image files that were intended to be protected.

Affected Systems

Any deployment of WWBN AVideo before commit c3edcc274c389816d434acadac07ee78eaf330c1 that exposes the ImageGallery list.json.php endpoint to the public web is affected. This includes installations that have not applied the patch for the missing authorization check.

Risk and Exploitability

The CVSS score of 6.9 indicates a moderate to high severity, and the EPSS score of less than 1% suggests a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalogue. Attackers can reach the compromised endpoint over the web, retrieve file paths and URLs, representing a direct confidentiality breach for any gallery that was intended to be password‑protected.

Generated by OpenCVE AI on September 15, 2026 at 18:48 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest AVideo release that includes proper authorization for the ImageGallery list.json.php endpoint
  • Configure the web server to require authentication or IP filtering for the ImageGallery list.json.php endpoint, and verify that password‑protected galleries are not served publicly
  • Configure logging or monitoring to detect and alert on attempts to access protected image galleries via the public endpoint

Generated by OpenCVE AI on September 15, 2026 at 18:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 12 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Description WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate user permissions in the ImageGallery list.json.php endpoint, allowing unauthenticated access to list gallery files. Attackers can retrieve filenames and URLs of password-protected image galleries by directly accessing the endpoint, then fetch the exposed files without authentication.
Title WWBN AVideo Missing Authorization in ImageGallery list.json.php
First Time appeared Wwbn
Wwbn avideo
Weaknesses CWE-200
CPEs cpe:2.3:a:wwbn:avideo:-:*:*:*:*:*:*:*
Vendors & Products Wwbn
Wwbn avideo
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-14T18:26:32.649Z

Reserved: 2026-09-12T11:13:17.618Z

Link: CVE-2026-90548

cve-icon Vulnrichment

Updated: 2026-09-14T18:26:27.537Z

cve-icon NVD

Status : Deferred

Published: 2026-09-12T13:16:53.187

Modified: 2026-09-14T21:07:11.883

Link: CVE-2026-90548

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T19:00:15Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor