SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-90545

MEDIUM · CVSS 4.3 EPSS 0.18% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-12 · Last synced 2026-09-13

CyberRota Analysis

AI-Generated

The vulnerability allows authenticated users to bypass access controls in the commentAddNew.json.php endpoint of WWBN AVideo, enabling them to post comments on password-protected and group-restricted videos. This could lead to unauthorized interactions with sensitive content, potentially exposing private discussions or information. Organizations using AVideo should prioritize addressing this issue to prevent unauthorized access and maintain content confidentiality.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-90545
Severity
MEDIUM
CVSS
4.3
EPSS
0.18%

Original NVD Description

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate video access permissions in the commentAddNew.json.php endpoint, allowing authenticated users to post comments on password-protected and group-restricted videos. Attackers can submit POST requests with a valid session to add comments to videos they cannot watch, bypassing password and group access controls.