๐Ÿ” CVE Alert

CVE-2026-84480

CRITICAL 9.8

WWBN AVideo Password Recovery Token Expiration Bypass

CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th

WWBN AVideo fails to validate password recovery token expiration in userRecoverPassSave.json.php, allowing attackers to use expired tokens to reset account passwords indefinitely. Attackers who obtain a recovery token can use it at any time to change the target account's password and gain full account access.

CWE CWE-613
Vendor wwbn
Product avideo
Published Sep 1, 2026
Stay Ahead of the Next One

Get instant alerts for wwbn avideo

Be the first to know when new critical vulnerabilities affecting wwbn avideo are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

WWBN / AVideo
0 โ‰ค 29.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/WWBN/AVideo/security/advisories/GHSA-j9p7-hm85-9v77 vulncheck.com: https://www.vulncheck.com/advisories/wwbn-avideo-password-recovery-token-expiration-bypass

Credits

๐Ÿ” rajivraj