CVE-2026-89251: AVideo Missing Authorization via AD_Server log.php Wallet Credit

Published Sep 11, 2026
·
Updated

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate ad impressions in plugin/ADServer/log.php, allowing logged-in users to submit arbitrary label values that trigger unverified wallet credits to campaign video owners. Attackers can repeatedly POST label=start requests to mint YPTWallet balance for any campaign video without proof an ad actually played.

Affected Software

1 affected component
AVideo AVideo

Event History

Sep 11, 2026
CVE Published
via MITRE·11:15 AM
Data Sourced
via MITRE·11:15 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An attacker needs to be logged in to AVideo and able to send POST requests to the affected AD_Server logging endpoint. No user interaction or actual advertisement playback is required.

2

What is the practical impact of exploitation?

A logged-in attacker can repeatedly submit label=start requests for campaign videos and cause unverified YPTWallet credits to be issued to those videos' owners. This affects wallet balance integrity rather than confidentiality or service availability.

3

Are normal ad-impression checks sufficient to prevent abuse?

No. The affected endpoint does not validate that an ad impression occurred before issuing the wallet credit, so an attacker can mint credits without proof that the ad played.

4

What can be done if an update is not immediately available?

Restrict access to the affected AD_Server logging endpoint to trusted application traffic and monitor for repeated or anomalous label=start POST requests. Review wallet-credit activity for campaign videos that lacks corresponding verified ad-play evidence.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203