CVE-2026-90548: WWBN AVideo Missing Authorization in ImageGallery list.json.php

Published Sep 12, 2026
·
Updated

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate user permissions in the ImageGallery list.json.php endpoint, allowing unauthenticated access to list gallery files. Attackers can retrieve filenames and URLs of password-protected image galleries by directly accessing the endpoint, then fetch the exposed files without authentication.

Affected Software

1 affected component
AVideo>undefined

Event History

Sep 12, 2026
CVE Published
via MITRE·12:08 PM
Data Sourced
via MITRE·12:08 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

Any unauthenticated remote attacker who can reach the ImageGallery list.json.php endpoint can exploit it. No credentials or user interaction are required.

2

What information and content can be exposed?

The endpoint can disclose filenames and URLs for password-protected image galleries. An attacker can then retrieve the exposed gallery files without authentication.

3

How can I determine whether my deployment is affected?

AVideo versions through commit c3edcc274c389816d434acadac07ee78eaf330c1 are affected. A deployment is vulnerable if an unauthenticated request to the ImageGallery list.json.php endpoint returns gallery file listings or URLs for password-protected galleries.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203