CVE-2026-92585
AVideo through 29.0 Missing Authorization Check via API Like Endpoint
CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th
AVideo through 29.0 (commit c3edcc274c389816d434acadac07ee78eaf330c1) fails to validate video access permissions in the API like endpoint, allowing logged-in users to vote on password-protected and group-restricted videos. Attackers can submit like and dislike requests to increment vote counters on videos they cannot watch by calling the set.json.php endpoint with APIName parameters.
| CWE | CWE-862 |
| Vendor | wwbn |
| Product | avideo |
| Published | Sep 16, 2026 |
Stay Ahead of the Next One
Get instant alerts for wwbn avideo
Be the first to know when new medium vulnerabilities affecting wwbn avideo are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
None
Affected Versions
WWBN / AVideo
0 โค c3edcc274c389816d434acadac07ee78eaf330c1 0 โค 29.0
References
Credits
๐ santhreal