Description
WWBN AVideo through 29.0 contains an authentication bypass vulnerability where the stored password hash is accepted as a valid login credential through two independent code paths in loginFromRequest() and encryptPasswordVerify(). Attackers who obtain the stored users.password hash value can authenticate as any user by submitting the hash directly to login endpoints, completely bypassing password verification.
Published: 2026-09-16
Score: 9.2 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Authentication Bypass
Action: Immediate Patch
AI Analysis

Impact

The vulnerability allows attackers to authenticate as any user by submitting the stored password hash directly to login endpoints, bypassing password verification. Two code paths, loginFromRequest() and encryptPasswordVerify(), accept the hash as a valid credential. Based on the description, the attacker can impersonate any user, potentially including accounts with administrative rights. This flaw is classified as CWE‑287 with a CVSS score of 9.2.

Affected Systems

WWBN AVideo, versions 29.0 and earlier. All installs of AVideo through release 29.0 are vulnerable.

Risk and Exploitability

The CVSS score of 9.2 renders the vulnerability critical. The EPSS score is below 1 %, indicating a low probability of exploitation at this time, and the issue is not listed in CISA’s KEV catalog. Based on the description, the attacker would need to have access to the stored password hash. No additional conditions are stated, so the flaw can be leveraged without further prerequisites.

Generated by OpenCVE AI on September 17, 2026 at 22:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade AVideo to a patch release that removes the ability to submit raw password hashes in login end points
  • If immediate upgrade is infeasible, restrict external access to the login API by firewall rules or VPN, limiting use to trusted IP ranges
  • Apply custom server‑side validation that rejects any supplied hash and enforces proper hashing and comparison logic, ensuring only hashed passwords can be verified

Generated by OpenCVE AI on September 17, 2026 at 22:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description WWBN AVideo through 29.0 contains an authentication bypass vulnerability where the stored password hash is accepted as a valid login credential through two independent code paths in loginFromRequest() and encryptPasswordVerify(). Attackers who obtain the stored users.password hash value can authenticate as any user by submitting the hash directly to login endpoints, completely bypassing password verification.
Title WWBN AVideo through 29.0 Authentication Bypass via Stored Password Hash
First Time appeared Wwbn
Wwbn avideo
Weaknesses CWE-287
CPEs cpe:2.3:a:wwbn:avideo:*:*:*:*:*:*:*:*
Vendors & Products Wwbn
Wwbn avideo
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-17T14:52:56.526Z

Reserved: 2026-09-16T13:47:20.117Z

Link: CVE-2026-92578

cve-icon Vulnrichment

Updated: 2026-09-17T14:52:51.723Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T22:18:28.053

Modified: 2026-09-22T20:43:58.793

Link: CVE-2026-92578

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T22:30:17Z

Weaknesses