CVE-2026-85154: WWBN AVideo Authentication Bypass via Non-Expiring video_id_hash

Published Sep 3, 2026
·
Updated

WWBN AVideo contains an authentication failure vulnerability where the videoidhash credential is a non-expiring, non-revocable bearer token that grants full administrator session access to the video owner's account. Attackers who obtain a videoidhash can replay it indefinitely to authenticate as the video owner with full privileges, and the credential remains valid even after the owner changes their password.

Affected Software

1 affected component
WWBN AVideo

Event History

Sep 3, 2026
CVE Published
via MITRE·11:22 AM
Data Sourced
via MITRE·11:22 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What must an attacker obtain to exploit this issue?

An attacker needs a valid video_id_hash credential for a video. That value can then be replayed as a bearer token to authenticate as the video owner.

2

What level of access does a compromised video_id_hash provide?

The credential grants full administrator session access to the account that owns the associated video. Exploitation requires no privileges or user interaction once the attacker has the hash.

3

Will changing the affected account's password invalidate a stolen credential?

No. The video_id_hash remains valid after the owner changes their password, so password reset alone does not remove an attacker's access.

4

How long can a stolen video_id_hash be used?

It can be replayed indefinitely because the credential is non-expiring and non-revocable.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203