CVE-2026-86722: AVideo Authentication Bypass via SQL Cache Invalidation

Published Sep 8, 2026
·
Updated

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains an authentication bypass vulnerability where sqlDAL caches empty result sets that writeSql never invalidates. Attackers with a valid password can bypass email two-factor authentication on new devices because the confirmation code hash fails to generate from the stale cached empty result.

Affected Software

1 affected component
AVideo AVideo>=c3edcc274c389816d434acadac07ee78eaf330c1<

Event History

Sep 8, 2026
CVE Published
via MITRE·03:13 PM
Data Sourced
via MITRE·03:13 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An attacker needs a valid password for an AVideo account. The issue affects attempts to sign in from a new device where email two-factor authentication would normally be required.

2

What security control can be bypassed?

The vulnerability allows bypass of email-based two-factor authentication. It does not indicate that an attacker can authenticate without first having a valid password.

3

How does the bypass occur?

AVideo's sqlDAL can cache an empty result set, and writeSql does not invalidate that cached result. As a result, the confirmation-code hash may not be generated, allowing the email two-factor check to be bypassed on a new device.

4

Which versions are affected?

The available information states that AVideo is affected through commit c3edcc274c389816d434acadac07ee78eaf330c1. No release-version range is provided.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203