WWBN AVideo contains a broken access control vulnerability in its videoViewsInfo endpoints. The flaw allows unauthenticated callers to retrieve complete user records, including password hashes, recovery tokens, and live session identifiers, simply by providing a hash parameter. Attackers can exploit disclosed session identifiers to hijack active viewer sessions, including those belonging to administrator accounts. This exposure also risks leaking sensitive personal data for all video viewers. The vulnerability is classified under CWE broken access control and has been assigned CVE-2026-86190. Advisories have been published by both GitHub Security Advisories and VulnCheck. The severity is considered high due to the potential for full account takeover and mass data exposure.