CVE-2026-86190
Last modified
CVE-2026-86190 is a critical-severity vulnerability rated 9.1/10 on the CVSS scale. WWBN AVideo contains a broken access control vulnerability in videoViewsInfo endpoints that returns complete user records including password hashes, recovery tokens, and live session identifiers to unauthenticated callers when a hash parameter is provided. Attackers can use the disclosed session identifier to hijack viewer sessions, including administrator accounts, and obtain sensitive personal data for all video viewers.. EPSS estimates a 0.27% chance of exploitation in the next 30 days.
Description
WWBN AVideo contains a broken access control vulnerability in videoViewsInfo endpoints that returns complete user records including password hashes, recovery tokens, and live session identifiers to unauthenticated callers when a hash parameter is provided. Attackers can use the disclosed session identifier to hijack viewer sessions, including administrator accounts, and obtain sensitive personal data for all video viewers.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| WWBN | AVideo | <= 29.0 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-86190?
How severe is CVE-2026-86190?
How do I fix CVE-2026-86190?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-86185Bilibili Desktop through 1.18.0 disables TLS certificate ver…8
- CVE-2026-86186AVideo API fails to enforce rate limits when clients send a …6.5
- CVE-2026-86187WWBN AVideo generates passwords for external-login accounts …5.9
- CVE-2026-86188AVideo with YPTSocket plugin enabled contains a cross-site s…7.2
- CVE-2026-86189WWBN AVideo contains a path traversal vulnerability in notif…9.8
- CVE-2026-8619An unauthenticated denial-of-service vulnerability was ident…7.5
- CVE-2026-86191SiYuan versions before v3.8.2 contain an information disclos…4.3
- CVE-2026-86192SiYuan versions before v3.8.2 fail to properly filter privat…6.5
- CVE-2026-86193grav-plugin-api before 1.0.20 fails to validate group-inheri…8.7
- CVE-2026-86194Grav Form Plugin before 9.1.22 fails to verify page authoriz…6.9
- CVE-2026-86195grav-plugin-api versions before 1.0.20 contain a privilege e…8.7
- CVE-2026-86196Grav API plugin versions before 1.0.20 build password reset …8.7
Are you affected by CVE-2026-86190?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
