VYPR
High severity7.5NVD Advisory· Published Sep 10, 2026· Updated Sep 10, 2026

CVE-2026-88876

CVE-2026-88876

Description

AVideo through revision c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in plugin/PlayerSkins/seo.php that allows unauthenticated attackers to access password-protected video sources by calling getSources() without password validation. Attackers can request the seo.php endpoint with a video ID to obtain the direct MP4 URL and read protected media bytes without supplying the configured password.

Affected products

3
  • AVideo/AVideollm-fuzzy
    Range: <c3edcc274c389816d434acadac07ee78eaf330c1
  • WWBN/Avideollm-fuzzy2 versions
    <c3edcc274c389816d434acadac07ee78eaf330c1+ 1 more
    • (no CPE)range: <c3edcc274c389816d434acadac07ee78eaf330c1
    • (no CPE)range: <=c3edcc274c389816d434acadac07ee78eaf330c1

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.