VYPR
Published Sep 5, 2026· Updated Sep 8, 2026· 1 source

WWBN AVideo: 25 Vulnerabilities Disclosed in Early September 2026 Batch

Key findings • 25 WWBN AVideo vulnerabilities disclosed between Sep 1-5, 2026, including critical flaws. • Critical vulnerabilities include indefinite password resets, auth bypasses, and path…

Key findings

  • 25 WWBN AVideo vulnerabilities disclosed between Sep 1-5, 2026, including critical flaws.
  • Critical vulnerabilities include indefinite password resets, auth bypasses, and path traversal.
  • High-severity issues encompass CSRF, SSRF, and rate limit bypasses.
  • Multiple XSS, CSRF, and broken access control flaws also impact the platform.
  • All disclosed vulnerabilities are addressed in commit e01e41ecc and later versions.

On September 5, 2026, a significant batch of 25 vulnerabilities affecting WWBN's AVideo platform was disclosed, with the majority of these disclosures occurring between September 1st and September 5th, 2026. This cluster of vulnerabilities spans critical, high, and medium severity flaws, impacting authentication, access control, and data integrity. The vulnerabilities were disclosed by multiple sources, highlighting a broad security concern for AVideo users.

Several critical vulnerabilities were detailed, including CVE-2026-86190, a broken access control flaw in videoViewsInfo endpoints that exposes user records, password hashes, and session identifiers to unauthenticated callers. CVE-2026-86189, a path traversal vulnerability in notify.ffmpeg.json.php, allows unauthenticated attackers to write files to arbitrary locations. Additionally, CVE-2026-84208 and CVE-2026-84480 present critical SQL injection and indefinite password reset capabilities, respectively, allowing attackers to gain full account access. CVE-2026-84479, also critical, relies on client-supplied User-Agent headers for security controls, enabling authentication bypasses.

High-severity vulnerabilities include CVE-2026-86188, a cross-site scripting (XSS) flaw in the YPTSocket plugin, and CVE-2026-85164, a server-side request forgery (SSRF) vulnerability in the set_api_userImages API endpoint. CVE-2026-85160 combines cross-site request forgery (CSRF) and path traversal in stopLive.php, allowing directory deletion. CVE-2026-84482 presents a critical CSRF vulnerability due to improper referer origin validation, and CVE-2026-84476 allows for rate limit bypass via spoofed client addresses, enabling unlimited credential guessing. CVE-2026-84478, a path traversal vulnerability, enables arbitrary log file deletion. CVE-2026-85155 is a SQL injection vulnerability in the get.json.php endpoint that can lead to the inference of user passwords.

Medium-severity issues also present significant risks. CVE-2026-86187 and CVE-2026-85186 highlight weaknesses in password generation and API rate limiting, respectively. Several cross-site request forgery (CSRF) vulnerabilities, including CVE-2026-85163, CVE-2026-85162, and CVE-2026-85160, allow attackers to hijack live broadcasts or delete content. Reflected XSS vulnerabilities are present in CVE-2026-85577 and CVE-2026-85159. Broken access control flaws in CVE-2026-85157 and CVE-2026-85156 permit unauthorized access to restricted videos. Information disclosure vulnerabilities like CVE-2026-84481 expose sensitive configuration data. CVE-2026-84477 details stored XSS in the Live_schedule plugin.

The vulnerabilities were addressed in commit e01e41ecc and later versions of AVideo. Users are strongly advised to update to patched versions to mitigate these security risks. The widespread nature of these vulnerabilities underscores the importance of timely patching and security audits for AVideo deployments.

The disclosure of this large batch of vulnerabilities, particularly those with critical and high severity ratings, presents a substantial risk to WWBN AVideo users. The flaws impact core functionalities such as authentication, password recovery, and access control, potentially leading to complete account compromise and unauthorized data access. Prompt patching is essential to protect against exploitation.

Synthesized by Vypr AI