CVE-2026-84480
published 2026-09-01CVE-2026-84480: WWBN AVideo fails to validate password recovery token expiration in userRecoverPassSave.json.php, allowing attackers to use expired tokens to reset account…
PriorityP260critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.51%
41.3th percentile
WWBN AVideo fails to validate password recovery token expiration in userRecoverPassSave.json.php, allowing attackers to use expired tokens to reset account passwords indefinitely. Attackers who obtain a recovery token can use it at any time to change the target account's password and gain full account access.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| wwbn | avideo | <= 29.0 | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.09.3CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
WWBN AVideo up to 29.0 userRecoverPassSave.json.php password recovery (EUVD-2026-69722)
vuldb·2026-09-02·CVSS 9.8
CVE-2026-84480 [CRITICAL] WWBN AVideo up to 29.0 userRecoverPassSave.json.php password recovery (EUVD-2026-69722)
A vulnerability marked as critical has been reported in WWBN AVideo up to 29.0. Affected by this vulnerability is an unknown functionality of the file userRecoverPassSave.json.php. Performing a manipulation results in weak password recovery.
This vulnerability is reported as CVE-2026-84480. The attack is possible to be carried out remotely. No exploit exists.
GHSA
WWBN AVideo fails to validate password recovery token expiration in userRecoverPassSave.json.php, allowing attackers to use expired tokens to reset account passwords indefinitely.
ghsa_unreviewed·2026-09-02
CVE-2026-84480 [CRITICAL] CWE-613 WWBN AVideo fails to validate password recovery token expiration in userRecoverPassSave.json.php, allowing attackers to use expired tokens to reset account passwords indefinitely.
WWBN AVideo fails to validate password recovery token expiration in userRecoverPassSave.json.php, allowing attackers to use expired tokens to reset account passwords indefinitely. Attackers who obtain a recovery token can use it at any time to change the target account's password and gain full account access.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-09-01
Published