CVE-2026-90549: WWBN AVideo Missing Authorization via videosAndroid.json.php Endpoint

Published Sep 12, 2026
·
Updated

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to properly authorize access to the videosAndroid.json.php endpoint, allowing unauthenticated guests to list password-protected videos with sensitive owner information. Attackers can retrieve video metadata including owner email, lastLogin, filename, and hashId by sending an unauthenticated GET request to the endpoint.

Affected Software

1 affected component
WWBN AVideo=commit c3edcc274c389816d434acadac07ee78eaf330c1

Event History

Sep 12, 2026
CVE Published
via MITRE·12:08 PM
Data Sourced
via MITRE·12:08 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

Any unauthenticated remote user can exploit it. No credentials or user interaction are required; the attacker only needs to send a GET request to the affected endpoint.

2

What information can be exposed?

The endpoint can list password-protected videos and disclose associated metadata, including the video owner’s email address, lastLogin value, filename, and hashId.

3

Are password-protected videos sufficient to prevent this disclosure?

No. The affected endpoint can expose listings and metadata for password-protected videos to unauthenticated guests.

4

How can I check whether an instance is affected?

Test whether an unauthenticated GET request to videosAndroid.json.php returns video listings or metadata such as owner email, lastLogin, filename, or hashId. The issue is reported in WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203