Description
In AVideo through 29.0, the API get_api_video endpoint contains a broken access control vulnerability in the clean_title branch that returns user-group-restricted videos with owner PII to anonymous callers. Attackers can query videos by their public slug to bypass group restrictions and retrieve sensitive user fields including email, phone, address, birth date, and administrator status.
Published: 2026-09-16
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Exfiltration of personal data
Action: Patch
AI Analysis

Impact

The AVideo API endpoint get_api_video contains a broken access control flaw in the clean_title branch that allows an unauthenticated user to query videos by their public slug. This flaw returns video entries that are restricted to specific user groups, but it also leaks owner Personally Identifiable Information including email, phone number, mailing address, birth date, and administrative status. The weakness is classified as CWE‑639, representing an authorization bypass through a user‑controlled key.

Affected Systems

The vulnerability affects all releases of WWBN AVideo up to and including version 29.0. The affected component is the server side API that processes the get_api_video request using clean_title parameters.

Risk and Exploitability

With a CVSS score of 8.7, the vulnerability is considered high severity. The EPSS score is less than 1 %, suggesting a low likelihood of exploitation at this time, and the issue is not listed in CISA’s KEV catalog. Because the endpoint is publicly accessible, an attacker needs only to know or guess a video slug to trigger the flaw and retrieve the exposed PII. No authentication or special privileges are required for exploitation, making the attack vector straightforward via standard HTTP requests.

Generated by OpenCVE AI on September 18, 2026 at 05:26 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to AVideo v29.1 or a later version that removes the broken access control in get_api_video.
  • If an upgrade cannot be applied immediately, configure the API to require authentication for the get_api_video endpoint and restrict access to user‑group‑restricted videos only to logged‑in users.
  • As a temporary workaround, disable or modify the clean_title feature for the public API so that it performs proper group checks before returning any video metadata or owner PII.

Generated by OpenCVE AI on September 18, 2026 at 05:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description In AVideo through 29.0, the API get_api_video endpoint contains a broken access control vulnerability in the clean_title branch that returns user-group-restricted videos with owner PII to anonymous callers. Attackers can query videos by their public slug to bypass group restrictions and retrieve sensitive user fields including email, phone, address, birth date, and administrator status.
Title AVideo through 29.0 API get_api_video Broken Access Control via clean_title
First Time appeared Wwbn
Wwbn avideo
Weaknesses CWE-639
CPEs cpe:2.3:a:wwbn:avideo:*:*:*:*:*:*:*:*
Vendors & Products Wwbn
Wwbn avideo
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-17T19:23:51.702Z

Reserved: 2026-09-16T13:47:20.117Z

Link: CVE-2026-92577

cve-icon Vulnrichment

Updated: 2026-09-17T19:15:45.431Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T22:18:27.910

Modified: 2026-09-22T20:43:58.793

Link: CVE-2026-92577

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T20:45:14Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key