CVE-2026-84480: WWBN AVideo Password Recovery Token Expiration Bypass
WWBN AVideo fails to validate password recovery token expiration in userRecoverPassSave.json.php, allowing attackers to use expired tokens to reset account passwords indefinitely. Attackers who obtain a recovery token can use it at any time to change the target account's password and gain full account access.
Affected Software
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
The attacker must obtain a password recovery token for the target account. No authentication or user interaction is required to submit an expired token and reset the password.
Who is exposed to account takeover?
Any account for which an attacker has obtained a password recovery token may be exposed, because expired tokens remain usable indefinitely. Successful exploitation gives the attacker full access to the affected account.
How can I tell whether a token has been abused?
The provided information does not identify specific logs, indicators, or detection methods. Investigate unexpected password changes and account access, particularly where password recovery tokens may have been exposed.