PT-2026-84986 · Wwbn · Avideo

·

CVE-2026-85154

·

Published

2026-09-03

·

Updated

2026-09-08

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WWBN AVideo versions prior to 29.0
Description An authentication failure exists where the video id hash acts as a non-expiring and non-revocable bearer token. A bearer token is a security token that grants access to whoever possesses it. This flaw allows an attacker who obtains a video id hash to replay it indefinitely to authenticate as the video owner, granting full administrator session access and privileges. Because the token is non-revocable, it remains valid even after the account owner changes their password.
Recommendations Update WWBN AVideo to a version newer than 29.0. Review web and access logs for unexpected authenticated sessions. Rotate affected credentials where supported.

Exploit

Fix

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-85154
GHSA-59P8-6M2V-GCR5

Affected Products

Avideo