High severity8.8NVD Advisory· Published Aug 22, 2026
CVE-2026-59808
CVE-2026-59808
Description
AVideo through commit 9c39d8c8 contains an authentication bypass vulnerability where deduplicateByEncoderQueueId() returns video_id_hash credentials for any video by encoder_queue_id without ownership verification, and useVideoHashOrLogin() converts this hash into passwordless login as the video owner. Attackers with upload permission can retrieve an administrator's video_id_hash by omitting the videos_id parameter, then use that hash in an unauthenticated request to gain administrative session access and modify system configuration.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.