High severity7.5NVD Advisory· Published Sep 10, 2026· Updated Sep 10, 2026
CVE-2026-88876
CVE-2026-88876
Description
AVideo through revision c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in plugin/PlayerSkins/seo.php that allows unauthenticated attackers to access password-protected video sources by calling getSources() without password validation. Attackers can request the seo.php endpoint with a video ID to obtain the direct MP4 URL and read protected media bytes without supplying the configured password.
Affected products
3Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.