Description
AVideo LoginControl contains an authentication bypass vulnerability in the PGP second factor verification that compares challenge responses using loose equality against an uninitialized session variable. Attackers with a victim's password can bypass the second factor by sending a parameter-less GET request to verifyChallenge.json.php, which evaluates null == null and marks authentication complete.
Published: 2026-09-17
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Authentication bypass via second factor
Action: Immediate Patch
AI Analysis

Impact

AVideo LoginControl contains a flaw in its PGP second factor verification where the challenge response is compared using loose equality against an uninitialized session variable. This leads to null == null being true, allowing an attacker who knows a victim’s password to complete authentication without supplying a second factor. The vulnerability enables an attacker to gain authenticated access to the system by simply requesting the verifyChallenge endpoint with no parameters, thereby bypassing the intended two‑factor protection.

Affected Systems

The weakness affects the AVideo content‑management platform developed by WWBN. No specific version information is provided in the advisory, so all installations of AVideo should be evaluated for the presence of the unauthenticated verifyChallenge.json.php handler.

Risk and Exploitability

The CVSS score of 8.6 classifies this defect as high severity. EPSS information is not available, but the attack requires only a valid password and a simple HTTP GET request, so it can be remotely exploited via the public web interface. The vulnerability is not currently listed in the CISA KEV catalog, indicating no known widespread exploitation, yet the high impact and remote nature warrant close attention.

Generated by OpenCVE AI on September 18, 2026 at 06:54 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update AVideo to the latest release that contains the fix for the verifyChallenge flaw.
  • If an update is not immediately available, disable or remove the PGP second‑factor component until the patch is applied to prevent unauthorized bypass.
  • Monitor authentication logs for unusual login patterns and enforce password rotation policies to reduce the risk from compromised credentials.

Generated by OpenCVE AI on September 18, 2026 at 06:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Description AVideo LoginControl contains an authentication bypass vulnerability in the PGP second factor verification that compares challenge responses using loose equality against an uninitialized session variable. Attackers with a victim's password can bypass the second factor by sending a parameter-less GET request to verifyChallenge.json.php, which evaluates null == null and marks authentication complete.
Title AVideo LoginControl PGP Second Factor Authentication Bypass
First Time appeared Wwbn
Wwbn avideo
Weaknesses CWE-287
CPEs cpe:2.3:a:wwbn:avideo:*:*:*:*:*:*:*:*
Vendors & Products Wwbn
Wwbn avideo
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}

cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-17T19:22:52.032Z

Reserved: 2026-09-17T11:07:29.772Z

Link: CVE-2026-92914

cve-icon Vulnrichment

Updated: 2026-09-17T19:17:12.210Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T12:18:30.440

Modified: 2026-09-22T20:43:58.793

Link: CVE-2026-92914

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T07:30:05Z

Weaknesses