CVE-2026-90537: WWBN AVideo Scheduler sendEmail Missing Authorization via Token

Published Sep 12, 2026
·
Updated

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in plugin/Scheduler/sendEmail.json.php that allows unauthenticated attackers to access scheduler email jobs by providing a site-wide daily token. Attackers can enumerate scheduler jobs, read private live titles and email addresses, and trigger email sending by supplying any valid daily token obtained from Live pages.

Affected Software

1 affected component
WWBN AVideo Scheduler>=undefined

Event History

Sep 12, 2026
CVE Published
via MITRE·12:08 PM
Data Sourced
via MITRE·12:08 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What does an attacker need to exploit this issue?

An attacker needs any valid site-wide daily token obtained from Live pages. No authentication or user interaction is required.

2

Which data and actions are exposed?

An attacker can enumerate scheduler email jobs, read private live titles and email addresses, and trigger email sending through the affected Scheduler endpoint.

3

Are installations affected by default?

The available information identifies the Scheduler plugin endpoint plugin/Scheduler/sendEmail.json.php as affected, but does not state whether the Scheduler plugin is enabled by default.

4

What can be done if patching is not immediately possible?

The provided information does not list a workaround. Restricting access to the affected Scheduler endpoint would address the exposed path, but no specific mitigation is documented in the supplied data.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203