CVE-2026-59256: WWBN AVideo Unbound Token Authorization Bypass via Gallery

Published Aug 22, 2026
·
Updated

WWBN AVideo through commit 9c39d8c8 contains an authorization bypass vulnerability where getToken() creates tokens without binding to user identity or purpose, and plugin/Gallery/view/sections.php issues valid tokens to unauthenticated visitors. Attackers can retrieve a token from the Gallery endpoint and use it to bypass authorization checks in other subsystems like view/hls.php to access restricted video content.

Affected Software

1 affected component
WWBN AVideo=commit 9c39d8c8

Event History

Aug 22, 2026
CVE Published
via MITRE·12:26 PM
Data Sourced
via MITRE·12:26 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:16 PM
DescriptionSeverityWeakness
Aug 20, 58611
Event
via NVD·01:30 AM

Frequently Asked Questions

1

Who can exploit this issue?

Any unauthenticated remote visitor who can reach the Gallery endpoint can obtain a valid token. No account, privileges, or user interaction are required.

2

What access can an attacker gain with a token obtained from Gallery?

The token can be used to bypass authorization checks in other subsystems, including view/hls.php, to access restricted video content. The available information identifies confidentiality impact only; it does not indicate integrity or availability impact.

3

Are deployments affected by default?

The issue is exposed when plugin/Gallery/view/sections.php is reachable by unauthenticated visitors, because that endpoint issues valid tokens. The provided information does not state whether Gallery is enabled or publicly accessible by default.

4

How can I check whether my instance is affected?

Review whether the deployment includes commit 9c39d8c8 or an affected version through that commit, and test whether an unauthenticated request to the Gallery endpoint receives a valid token. Also verify whether that token is accepted by protected endpoints such as view/hls.php.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203