Critical severity9.8NVD Advisory· Published Sep 3, 2026
CVE-2026-85154
CVE-2026-85154
Description
WWBN AVideo contains an authentication failure vulnerability where the video_id_hash credential is a non-expiring, non-revocable bearer token that grants full administrator session access to the video owner's account. Attackers who obtain a video_id_hash can replay it indefinitely to authenticate as the video owner with full privileges, and the credential remains valid even after the owner changes their password.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.