CVE-2026-90552
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate playlist ownership in the Playlists_schedules/list.json.php and Live/calendar.json.php endpoints, allowing authenticated and unauthenticated users to read private playlist schedule metadata. Attackers with canStream privileges or no authentication can retrieve schedule names, descriptions, timestamps, and playlist identifiers by querying these endpoints without ownership checks.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.3
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
- CWE
- CWE-639
- Published
- 2026-09-12
- Last modified
- 2026-09-12
Affected products
- WWBN AVideo
Weakness type
Related vulnerabilities
- CVE-2026-90542 — WWBN AVideo Missing Authorization via remindMe.json.php
- CVE-2026-90534 — Flowise before 3.1.4 Cross-Workspace Credential IDOR via node-load-method
- CVE-2026-54258 — Cross-monitor event media authorization bypass in direct event media endpoints
- CVE-2026-49464 — NL Portal: IDOR allows any authenticated user to complete and tamper with another user's taak
- CVE-2026-81916 — Incorrect Authorization in the Concrete CMS Express Entries Dashboard below version 9.5.3 Allows Entry Creation in an Unauthorized Object
- CVE-2026-81915 — In Concrete CMS below 9.5.3, Page Type update omits object-level authorization
- CVE-2026-62134 — WordPress Starter Templates plugin <= 4.7.5 - Insecure Direct Object References (IDOR) vulnerability
- CVE-2026-62113 — WordPress Slim SEO plugin <= 4.10.0 - Insecure Direct Object References (IDOR) vulnerability