PT-2026-94103 · Avideo · Avideo

·

CVE-2026-92586

·

Published

2026-09-16

·

Updated

2026-09-16

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions AVideo versions prior to 29.0 (commit c3edcc274c389816d434acadac07ee78eaf330c1)
Description Authenticated users can post comments on password-protected and group-restricted videos because the software fails to verify video access permissions in the set api comment() function. This allows attackers to submit POST requests to the comment API endpoint using arbitrary video IDs to write comments on videos they are not authorized to watch.
Recommendations Update to a version later than 29.0 (commit c3edcc274c389816d434acadac07ee78eaf330c1).

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92586
GHSA-FM4F-Q895-8JHC

Affected Products

Avideo