Critical severity9.8NVD Advisory· Published Sep 1, 2026
CVE-2026-84480
CVE-2026-84480
Description
WWBN AVideo fails to validate password recovery token expiration in userRecoverPassSave.json.php, allowing attackers to use expired tokens to reset account passwords indefinitely. Attackers who obtain a recovery token can use it at any time to change the target account's password and gain full account access.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.