VYPR
Medium severity5.4NVD Advisory· Published Sep 11, 2026

CVE-2026-89257

CVE-2026-89257

Description

AVideo through 29.0 contains an insecure direct object reference (IDOR) vulnerability in objects/categoryDeleteAssets.json.php. The endpoint validates only the Category::canCreateCategory() capability and a CSRF nonce before passing the attacker-supplied $_REQUEST['id'] to Category::deleteAssets(), which recursively removes {systemRootPath}videos/categories/assets/{id}/. It omits the Category::userCanEditCategory() ownership check enforced by the sibling Category::delete(). On installations where the non-default usersCanCreateNewCategories setting is enabled, an authenticated non-admin user with the canUpload capability can send a POST request with an arbitrary category ID and recursively delete any category's on-disk asset directory (icons/images). Category records and videos are not deleted. As of the advisory publication no patched version was available.

Affected products

2
  • WWBN/Avideoinferred2 versions
    <=29.0+ 1 more
    • (no CPE)range: <=29.0
    • (no CPE)range: <=29.0

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.