PT-2026-94095 · Wwbn · Avideo

·

CVE-2026-92578

·

Published

2026-09-16

·

Updated

2026-09-16

CVSS v4.0

9.2

Critical

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions WWBN AVideo versions prior to 29.0
Description An authentication bypass exists where the stored password hash is accepted as a valid login credential. This occurs through two independent code paths in the loginFromRequest() and encryptPasswordVerify() functions. Attackers who obtain the stored users.password hash value can authenticate as any user by submitting the hash directly to login endpoints, bypassing password verification.
Recommendations Update to a version newer than 29.0.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92578
GHSA-FQ38-JP6C-Q4CX

Affected Products

Avideo