PT-2026-94102 · Avideo · Avideo

·

CVE-2026-92585

·

Published

2026-09-16

·

Updated

2026-09-19

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions AVideo versions prior to 29.0 (commit c3edcc274c389816d434acadac07ee78eaf330c1)
Description Logged-in users can vote on password-protected and group-restricted videos because the system fails to validate video access permissions in the API like endpoint. This allows attackers to increment vote counters on videos they are not authorized to watch by calling the 'set.json.php' endpoint using APIName parameters.
Recommendations Update to a version later than 29.0 (commit c3edcc274c389816d434acadac07ee78eaf330c1).

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92585
GHSA-RRCX-6VW7-XWJ8

Affected Products

Avideo