CVE-2026-85157: WWBN AVideo Broken Access Control via feed/index.php program_id

Published Sep 3, 2026
·
Updated

WWBN AVideo contains a broken access control vulnerability in the unauthenticated feed/index.php endpoint that disables per-video visibility checks when a programid parameter is supplied. Attackers can enumerate playlist identifiers and retrieve unlisted and group-restricted videos by requesting the RSS feed with any visible playlist id, including empty playlists that return the entire site's hidden video catalogue.

Affected Software

1 affected component
AVideo

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Compensating control

    Mitigate the broken access control by preventing unauthenticated access to the AVideo feed/index.php endpoint with a user-supplied program_id parameter (e.g., block or require authentication/authorization for requests that include program_id).

Event History

Sep 3, 2026
CVE Published
via MITRE·11:22 AM
Data Sourced
via MITRE·11:22 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

Any AVideo deployment with the unauthenticated feed/index.php endpoint reachable is exposed to unauthenticated retrieval of unlisted and group-restricted videos when the vulnerable parameter handling is present.

2

What does an attacker need to exploit it?

No authentication or user interaction is required. An attacker needs to request the RSS feed with a program_id value corresponding to a visible playlist identifier; an empty visible playlist can return the site's hidden video catalogue.

3

How can defenders determine whether restricted videos may already be exposed?

Review requests to feed/index.php that include the program_id parameter, particularly requests using playlist identifiers. Test whether a request using a visible or empty playlist ID returns videos that should be unlisted or restricted to a group.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203