Medium severity4.3NVD Advisory· Published Sep 16, 2026
CVE-2026-92581
CVE-2026-92581
Description
In AVideo through 29.0, Like::__construct() performs counter arithmetic on raw request values before validation, allowing array-typed parameters to desynchronize stored votes from counters. Authenticated attackers can send array-typed like parameters followed by ordinary requests to drive video like counts arbitrarily negative, with the corruption persisting in the denormalized counter until manual repair.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.