CVE-2026-90540: WWBN AVideo Missing Authorization via playListAddVideo.json.php
Published Sep 12, 2026
·Updated
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate watch permissions in the playListAddVideo.json.php endpoint when adding videos to playlists. Authenticated attackers can add password-protected videos they cannot watch to playlists they own by submitting the video ID and playlist ID parameters.
Affected Software
1 affected component
WWBN AVideo>undefined
Event History
Sep 12, 2026
CVE Published
via MITRE·12:08 PM
Data Sourced
via MITRE·12:08 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Does exploitation require an existing account?
Yes. The attacker must be authenticated, but only needs low-level privileges and does not require user interaction.
2
What builds are identified as affected?
WWBN AVideo is identified as affected through commit c3edcc274c389816d434acadac07ee78eaf330c1. No release-version mapping is provided.