VYPR
Vypr IntelligenceAI-generatedSep 1, 2026· 17 CVEs

WWBN AVideo: 16 Vulnerabilities Disclosed, Including Critical Auth and Password Reset Flaws

WWBN AVideo platform impacted by a batch of 16 vulnerabilities, including critical flaws in authentication and password recovery.

Key findings

On September 1, 2026, WWBN disclosed a significant batch of 16 vulnerabilities affecting its AVideo platform, with the majority of disclosures occurring on September 1st, following an initial set on August 30th. This cluster of vulnerabilities, spanning critical, high, and medium severities, highlights several weaknesses in authentication, authorization, and input validation across the platform and its plugins. The vulnerabilities were disclosed over a two-day period, from August 30th to September 1st, 2026.

Several critical and high-severity vulnerabilities were detailed in the disclosures. CVE-2026-84480, a critical flaw with a CVSS score of 9.8, allows attackers to indefinitely reset account passwords by exploiting an incomplete expiration check in the password recovery mechanism. Another critical vulnerability, CVE-2026-84479 (CVSSv3 9.1), found in commit e01e41ecc and earlier, relies solely on the client-supplied User-Agent header for critical login-time security controls, enabling unauthenticated attackers to bypass these checks.

High-severity issues include CVE-2026-84482 (CVSSv3 8.8), a cross-site request forgery (CSRF) vulnerability in AVideo's get_domain() and isSameDomain() functions, which could allow attackers to perform administrative actions. CVE-2026-84478 (CVSSv3 7.3) involves a path traversal vulnerability in the API get_api_login_code endpoint, enabling attackers to delete arbitrary log files. CVE-2026-84476 (CVSSv3 7.5) details a brute-force rate limiting bypass that can be exploited for unlimited credential guessing attacks. Additionally, CVE-2026-84483 (CVSSv3 5.3) presents an incomplete authentication bypass in encryptPass.json.php, allowing attackers to compute valid HMAC tokens. CVE-2026-84187 (CVSSv3 8.2) involves a missing authentication vulnerability in plugin/Live/on_publish.php, allowing unauthenticated attackers to mark broadcasts as failed. CVE-2026-83595 (CVSSv3 8.1) is another CSRF vulnerability in plugin/API/set.json.php, enabling state-changing actions. CVE-2026-8445 (CVSSv3 8.6) exposes stream credentials through an unprotected endpoint.

Medium-severity vulnerabilities were also present, including CVE-2026-84481 (CVSSv3 5.4), an information disclosure in the MobileManager plugin that leaks sensitive configuration data. CVE-2026-84477 (CVSSv3 5.4) is a stored cross-site scripting (XSS) vulnerability in the Live_schedule plugin. CVE-2026-82648 (CVSSv3 7.1) is a server-side request forgery (SSRF) filter bypass, and CVE-2026-82647 (CVSSv3 6.1) is a CSRF vulnerability in sendEmail.json.php. CVE-2026-82646 (CVSSv3 6.1) is an unauthenticated reflected XSS vulnerability in url2Embed.json.php. Finally, CVE-2026-82643 (CVSSv3 6.5) is an unauthenticated credential submission vulnerability in plugin/Live/api/preauthorize.json.php.

The vulnerabilities were addressed in commit e01e41ecc and later versions of AVideo. Users are strongly advised to update their AVideo installations to the latest available version to mitigate these risks. The wide range of issues, from authentication bypasses to information disclosure and XSS, underscores the importance of timely patching for all AVideo users to protect their platforms and user data.

The batch includes a mix of authentication bypasses, information disclosures, and cross-site scripting flaws. The critical CVE-2026-84480 allows indefinite password resets via expired tokens. CVE-2026-84479 and CVE-2026-84476 highlight weaknesses in rate limiting and authentication checks that can be bypassed. Several CSRF vulnerabilities, including CVE-2026-84482 and CVE-2026-83595, allow attackers to perform unauthorized actions. The SSRF bypass in CVE-2026-82648 is particularly concerning for cloud environments.

The disclosures span a variety of attack vectors, including direct API manipulation, forged requests, and client-side script injection. The vulnerabilities affect core functionalities such as password recovery, user authentication, stream management, and administrative actions. The prompt patching by WWBN, with fixes available in commit e01e41ecc and subsequent commits, is crucial for users to prevent exploitation.

This extensive set of vulnerabilities, disclosed in close succession, presents a significant risk to WWBN AVideo users. The presence of multiple critical and high-severity flaws, including those allowing for account takeover and sensitive data exposure, necessitates immediate attention. Users should prioritize updating their systems to the patched versions to safeguard against potential compromise. The breadth of the issues indicates a need for thorough security reviews of AVideo's codebase.

The vulnerabilities were fixed in commit e01e41ecc and later. Users should update to the latest version of AVideo to patch these issues. The batch includes critical flaws like CVE-2026-84480 (password reset) and CVE-2026-84479 (User-Agent based auth bypass). High-severity issues include CVE-2026-84482 (CSRF), CVE-2026-84478 (path traversal), and CVE-2026-84476 (rate limit bypass).

The WWBN AVideo platform experienced a significant security event with the disclosure of 16 vulnerabilities between August 30 and September 1, 2026. This batch includes critical and high-severity flaws impacting authentication, authorization, and data integrity. The vulnerabilities were patched in commit e01e41ecc and later.

The vulnerabilities were addressed in commit e01e41ecc and subsequent commits. Users are urged to update their AVideo installations promptly. The batch includes critical vulnerabilities such as CVE-2026-84480, which allows indefinite password resets, and CVE-2026-84479, which bypasses authentication controls based on the User-Agent header. High-severity flaws like CVE-2026-84482 (CSRF) and CVE-2026-84476 (rate limit bypass) are also present.

The batch of vulnerabilities disclosed for WWBN AVideo between August 30 and September 1, 2026, includes critical and high-severity flaws. These issues affect authentication, authorization, and input validation across the platform. The vulnerabilities were patched in commit e01e41ecc and later versions. Key issues include CVE-2026-84480 (password reset), CVE-2026-84479 (auth bypass), CVE-2026-84482 (CSRF), and CVE-2026-84476 (rate limit bypass).

The WWBN AVideo platform was affected by a batch of 16 vulnerabilities disclosed from August 30 to September 1, 2026. This cluster includes critical and high-severity flaws related to authentication bypass, password recovery, CSRF, and SSRF. All issues have been addressed in commit e01e41ecc and later. Users should update immediately.

The vulnerabilities were patched in commit e01e41ecc and later. The batch includes critical flaws like CVE-2026-84480 (password reset) and CVE-2026-84479 (User-Agent based auth bypass). High-severity issues include CVE-2026-84482 (CSRF), CVE-2026-84478 (path traversal), and CVE-2026-84476 (rate limit bypass). Users are urged to update their AVideo installations promptly.

The WWBN AVideo platform was impacted by a batch of 16 vulnerabilities disclosed between August 30 and September 1, 2026. This cluster includes critical and high-severity flaws affecting authentication, authorization, and data integrity. The vulnerabilities were patched in commit e01e41ecc and later versions. Key issues include CVE-2026-84480 (password reset), CVE-2026-84479 (auth bypass), CVE-2026-84482 (CSRF), and CVE-2026-84476 (rate limit bypass). Users should update immediately.

AI-written article. Grounded in 17 CVE records listed below.