Critical severity9.1NVD Advisory· Published Sep 5, 2026
CVE-2026-86190
CVE-2026-86190
Description
WWBN AVideo contains a broken access control vulnerability in videoViewsInfo endpoints that returns complete user records including password hashes, recovery tokens, and live session identifiers to unauthenticated callers when a hash parameter is provided. Attackers can use the disclosed session identifier to hijack viewer sessions, including administrator accounts, and obtain sensitive personal data for all video viewers.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.