Description
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate playlist ownership in the Playlists_schedules/list.json.php and Live/calendar.json.php endpoints, allowing authenticated and unauthenticated users to read private playlist schedule metadata. Attackers with canStream privileges or no authentication can retrieve schedule names, descriptions, timestamps, and playlist identifiers by querying these endpoints without ownership checks.
Published: 2026-09-12
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Apply Vendor Patch
AI Analysis

Impact

The flaw occurs because the system fails to validate playlist ownership before returning scheduling data. Either unauthenticated or canStream users can query the endpoints and receive schedule names, descriptions, timestamps, and playlist identifiers that should be protected.

Affected Systems

Affected installations of WWBN AVideo that include the Playlists_schedules/list.json.php or Live/calendar.json.php endpoints may be vulnerable. The vulnerability is present in the product as a missing ownership check; however, no specific affected-version details are available from the advisory.

Risk and Exploitability

The CVSS score of 5.3 indicates medium severity, while an EPSS score below 1% suggests low exploitation probability. The lack of authentication and a straightforward query path make it relatively easy for unauthenticated users to abuse the flaw. The vulnerability is not listed in the CISA KEV catalog, but the widespread availability of the vulnerable endpoints makes it a notable risk for any environment running WWBN AVideo.

Generated by OpenCVE AI on September 15, 2026 at 18:28 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest vendor patch or upgrade to a version that implements ownership checks on the list.json.php and calendar.json.php endpoints.
  • If a patch is not yet released, restrict network access to these endpoints to authenticated users with proper permissions, or block unauthenticated requests via a firewall or web server that may indicate exploitation attempts.
  • Conduct an audit of playlist ownership settings to ensure that only approved users can view schedule metadata, and adjust application-level permissions accordingly.

Generated by OpenCVE AI on September 15, 2026 at 18:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 12 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Description WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate playlist ownership in the Playlists_schedules/list.json.php and Live/calendar.json.php endpoints, allowing authenticated and unauthenticated users to read private playlist schedule metadata. Attackers with canStream privileges or no authentication can retrieve schedule names, descriptions, timestamps, and playlist identifiers by querying these endpoints without ownership checks.
Title WWBN AVideo Missing Authorization via Playlists_schedules list.json.php
First Time appeared Wwbn
Wwbn avideo
Weaknesses CWE-639
CPEs cpe:2.3:a:wwbn:avideo:-:*:*:*:*:*:*:*
Vendors & Products Wwbn
Wwbn avideo
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-15T17:06:07.584Z

Reserved: 2026-09-12T11:13:17.619Z

Link: CVE-2026-90552

cve-icon Vulnrichment

Updated: 2026-09-15T17:06:00.644Z

cve-icon NVD

Status : Deferred

Published: 2026-09-12T13:16:53.747

Modified: 2026-09-15T18:19:36.947

Link: CVE-2026-90552

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T18:30:14Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key