CVE-2026-90539: WWBN AVideo Missing Authentication via menuItems.json.php
Published Sep 12, 2026
·Updated
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authentication vulnerability in the plugin/TopMenu/menuItems.json.php endpoint that allows unauthenticated attackers to read inactive admin menu items by submitting a POST request with a menuId parameter. Attackers can retrieve hidden menu item URLs including embedded admin-tool secret query parameters not exposed in the public navbar.
Affected Software
1 affected component
WWBN AVideo>undefined
Event History
Sep 12, 2026
CVE Published
via MITRE·12:08 PM
Data Sourced
via MITRE·12:08 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What does an attacker need to exploit this issue?
An attacker can exploit it without authentication or user interaction by sending a POST request to the affected endpoint with a menuId parameter.
2
What information may be exposed?
The issue can disclose inactive administrative menu items, including hidden menu URLs and embedded secret query parameters for administrative tools.