Medium severity4.3NVD Advisory· Published Sep 12, 2026
CVE-2026-90544
CVE-2026-90544
Description
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate video access permissions in the videoAddViewCount.json.php endpoint before updating view statistics. Authenticated attackers can increment view counts and watch-time on videos they cannot access by submitting requests with arbitrary video IDs.
Affected products
2Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.