← Back to overview

WWBN AVideo contains a critical authentication failure vulnerability tracked as CVE-2026-85154. The vulnerability stems from the video_id_hash credential functioning as a non-expiring, non-revocable bearer token that grants full administrator session access to the video owner's account. Attackers who obtain a video_id_hash value can replay it indefinitely to authenticate as the video owner with full administrative privileges. The credential remains valid even after the account owner changes their password, eliminating the standard remediation path. This design flaw allows persistent unauthorized access with no built-in mechanism for revocation. The vulnerability represents a significant risk for any AVideo installation where a video_id_hash has been exposed or intercepted.

Affected products

  • WWBN AVideo

Related CVE's

  • CVE-2026-85154

Categories

  • Identity & Access
  • Web Technologies