CVE-2026-90544
published 2026-09-12CVE-2026-90544: WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate video access permissions in the videoAddViewCount.json.php endpoint…
PriorityP427medium4.3CVSS 3.1
AVNACLPRLUINSUCNILAN
EPSS
0.26%
16.8th percentile
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate video access permissions in the videoAddViewCount.json.php endpoint before updating view statistics. Authenticated attackers can increment view counts and watch-time on videos they cannot access by submitting requests with arbitrary video IDs.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| wwbn | avideo | <= c3edcc274c389816d434acadac07ee78eaf330c1 | — |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
nvdv4.05.3MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate video access permissions in the videoAddViewCount.json.php endpoint before updating view statistics.
ghsa_unreviewed·2026-09-12
CVE-2026-90544 [MEDIUM] CWE-862 WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate video access permissions in the videoAddViewCount.json.php endpoint before updating view statistics.
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate video access permissions in the videoAddViewCount.json.php endpoint before updating view statistics. Authenticated attackers can increment view counts and watch-time on videos they cannot access by submitting requests with arbitrary video IDs.
VulDB
WWBN AVideo videoAddViewCount.json.php permission
vuldb·2026-09-12·CVSS 4.3
CVE-2026-90544 [MEDIUM] WWBN AVideo videoAddViewCount.json.php permission
A vulnerability identified as problematic has been detected in WWBN AVideo. This affects an unknown function of the file videoAddViewCount.json.php. Performing a manipulation results in permission issues.
This vulnerability is known as CVE-2026-90544. Remote exploitation of the attack is possible. No exploit is available.
Applying a patch is the recommended action to fix this issue.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-09-12
Published