SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-90539

MEDIUM · CVSS 5.3 EPSS 0.24% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-12 · Last synced 2026-09-13

CyberRota Analysis

AI-Generated

The vulnerability exists in the plugin/TopMenu/menuItems.json.php endpoint of WWBN AVideo, where a lack of authentication allows unauthenticated attackers to access inactive admin menu items. This could lead to the exposure of sensitive URLs and admin-tool secret query parameters, potentially facilitating further attacks. Organizations using this software should prioritize patching this vulnerability to protect their administrative interfaces from unauthorized access.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-90539
Severity
MEDIUM
CVSS
5.3
EPSS
0.24%

Original NVD Description

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authentication vulnerability in the plugin/TopMenu/menuItems.json.php endpoint that allows unauthenticated attackers to read inactive admin menu items by submitting a POST request with a menuId parameter. Attackers can retrieve hidden menu item URLs including embedded admin-tool secret query parameters not exposed in the public navbar.