CVE-2026-90536

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to authorize access to the adsInfo API endpoint, allowing unauthenticated attackers to retrieve password-protected video owner identifiers. Attackers can call the adsInfo API with a videos_id parameter to obtain the owner's user ID and personalized ad creative URLs without authentication or permission checks.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-12 13:16

Updated : 2026-09-14 21:03


NVD link : CVE-2026-90536

Mitre link : CVE-2026-90536

CVE.ORG link : CVE-2026-90536


JSON object : View

Products Affected

No product.

CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor