CVE-2026-86190CWE-200information-disclosure

CVE-2026-86190

Critical · published September 5, 2026

CVSS v3.1
9.1
EPSS
In the wild
Unconfirmed
What it is

WWBN AVideo contains a broken access control vulnerability in videoViewsInfo endpoints that returns complete user records including password hashes, recovery tokens, and live session identifiers to unauthenticated callers when a hash parameter is provided. Attackers can use the disclosed session identifier to hijack viewer sessions, including administrator accounts, and obtain sensitive personal data for all video viewers.

The record
Technical detail
CVSS v3.1
9.1 · CRITICAL
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS v4.0
9.3 · CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
EPSS
Not scored
Weakness
CWE-200 · Exposure of Sensitive Information to an Unauthorized Actor
Published
2026-09-05T17:18Z
References (2)
Timeline
  • 05 SEP 12:09Z
    WWBN AVideo Broken Access Control via videoViewsInfo hash Parameter
    cvelistv5