SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-86190

CRITICAL · CVSS 9.1 EPSS 0.27% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-05 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

The vulnerability in WWBN AVideo allows unauthenticated users to access sensitive user records, including password hashes and session identifiers, through the videoViewsInfo endpoint when a hash parameter is supplied. This critical flaw enables attackers to hijack viewer sessions, potentially compromising administrator accounts and exposing personal data of all users. Organizations utilizing AVideo should prioritize immediate remediation to protect against unauthorized access and data breaches.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-86190
Severity
CRITICAL
CVSS
9.1
EPSS
0.27%

Original NVD Description

WWBN AVideo contains a broken access control vulnerability in videoViewsInfo endpoints that returns complete user records including password hashes, recovery tokens, and live session identifiers to unauthenticated callers when a hash parameter is provided. Attackers can use the disclosed session identifier to hijack viewer sessions, including administrator accounts, and obtain sensitive personal data for all video viewers.