CVE-2026-59256

WWBN AVideo through commit 9c39d8c8 contains an authorization bypass vulnerability where getToken() creates tokens without binding to user identity or purpose, and plugin/Gallery/view/sections.php issues valid tokens to unauthenticated visitors. Attackers can retrieve a token from the Gallery endpoint and use it to bypass authorization checks in other subsystems like view/hls.php to access restricted video content.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-22 13:16

Updated : 2026-08-26 18:16


NVD link : CVE-2026-59256

Mitre link : CVE-2026-59256

CVE.ORG link : CVE-2026-59256


JSON object : View

Products Affected

No product.

CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor