CVE-2026-90536: WWBN AVideo Missing Authorization via adsInfo API Endpoint
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to authorize access to the adsInfo API endpoint, allowing unauthenticated attackers to retrieve password-protected video owner identifiers. Attackers can call the adsInfo API with a videosid parameter to obtain the owner's user ID and personalized ad creative URLs without authentication or permission checks.
Affected Software
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
An attacker only needs network access to the AVideo instance and a videos_id value to call the adsInfo API endpoint. No authentication, permissions, or user interaction are required.
What information can be exposed?
The endpoint can disclose the user ID of the owner of a password-protected video and personalized advertising creative URLs associated with that video.
Are password-protected videos affected?
Yes. The disclosed owner identifiers are associated with password-protected videos, and the API endpoint does not enforce authorization checks before returning the information.
Which AVideo versions are affected?
The issue affects WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1. No fixed version is provided in the available information.