SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-90551

MEDIUM · CVSS 5.3 EPSS 0.24% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-12 · Last synced 2026-09-13

CyberRota Analysis

AI-Generated

The vulnerability allows unauthenticated users to access private playlist contents through the video_from_program API endpoint, enabling them to enumerate private playlist names, owner details, and video titles, including those that are password-protected. This poses a risk to any organization using the affected version of WWBN AVideo, particularly those handling sensitive or proprietary video content. Organizations should prioritize this issue to protect their users' privacy and prevent unauthorized access to confidential media.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-90551
Severity
MEDIUM
CVSS
5.3
EPSS
0.24%

Original NVD Description

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate playlist ownership in the video_from_program API endpoint, allowing unauthenticated access to private playlist contents. Attackers can query the API without authentication to enumerate private playlist names, owner information, and video titles including password-protected content.