PT-2026-79541 · Avideo · Avideo

·

CVE-2026-59808

·

Published

2026-08-22

·

Updated

2026-08-24

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions AVideo versions prior to commit 9c39d8c8
Description An authentication bypass exists where the deduplicateByEncoderQueueId() function returns video id hash credentials for any video based on the encoder queue id without verifying ownership. Subsequently, the useVideoHashOrLogin() function converts this hash into a passwordless login as the video owner. Users with upload permissions can retrieve an administrator's video id hash by omitting the videos id parameter, allowing them to use that hash in an unauthenticated request to obtain administrative session access and modify system configurations.
Recommendations Update AVideo to a version containing commit 9c39d8c8 or later.

Exploit

Fix

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-59808

Affected Products

Avideo