PT-2026-84542 · Wwbn · Avideo

·

CVE-2026-84483

·

Published

2026-09-01

·

Updated

2026-09-03

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions WWBN AVideo versions prior to commit 9c39d8c8
Description An incomplete authentication bypass exists in the 'encryptPass.json.php' endpoint. This flaw allows unauthenticated attackers to compute valid HMAC (Hash-based Message Authentication Code) tokens using the public site URL and the current time. By computing hash hmac with the site's base URL as the key, attackers can forge authentication tokens and submit arbitrary passwords to obtain encrypted hashes, which facilitates offline precomputation attacks against stolen password databases.
Recommendations Update WWBN AVideo to commit 9c39d8c8 or a later version. As a temporary mitigation, restrict access to the 'encryptPass.json.php' endpoint.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-84483

Affected Products

Avideo