PT-2026-84986 · Wwbn · Avideo
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
WWBN AVideo versions prior to 29.0
Description
An authentication failure exists where the
video id hash acts as a non-expiring and non-revocable bearer token. A bearer token is a security token that grants access to whoever possesses it. This flaw allows an attacker who obtains a video id hash to replay it indefinitely to authenticate as the video owner, granting full administrator session access and privileges. Because the token is non-revocable, it remains valid even after the account owner changes their password.Recommendations
Update WWBN AVideo to a version newer than 29.0.
Review web and access logs for unexpected authenticated sessions.
Rotate affected credentials where supported.
Exploit
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Avideo