CVE-2026-90546

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate video access permissions in the like.json.php endpoint, allowing logged-in users to record likes on password-protected and group-restricted videos. Attackers can submit like requests for videos they cannot watch to increment like counters and bypass access controls.

Scoring

Severity
MEDIUM
CVSS base score
5.3
CVSS vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
EPSS probability
0.21%
CWE
CWE-862
Published
2026-09-12
Last modified
2026-09-12

Affected products

Weakness type

Related vulnerabilities

Markdown version · Browse all CVEs