← Back to feed
Vulnerabilities & PatchesEmerging1 sourceSep 5, 2026 · 13:18via CVEFeed

CVE-2026-86190 - WWBN AVideo Broken Access Control via videoViewsInfo hash Parameter

Brief

CVE ID : CVE-2026-86190

Published : Sept. 5, 2026, 1:18 p. m.

  • 7 hours, 27 minutes ago

Description : WWBN AVideo contains a broken access control vulnerability in videoViewsInfo endpoints that returns complete user records including password hashes, recovery tokens, and live session identifiers to unauthenticated callers when a hash parameter is provided.

Attackers can use the disclosed session identifier to hijack viewer sessions, including administrator accounts, and obtain sensitive personal data for all video viewers.

Severity: 9.3

  • CRITICAL

Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Read more on CVEFeed