CVE-2026-90551

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate playlist ownership in the video_from_program API endpoint, allowing unauthenticated access to private playlist contents. Attackers can query the API without authentication to enumerate private playlist names, owner information, and video titles including password-protected content.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-12 13:16

Updated : 2026-09-14 21:03


NVD link : CVE-2026-90551

Mitre link : CVE-2026-90551

CVE.ORG link : CVE-2026-90551


JSON object : View

Products Affected

No product.

CWE
CWE-862

Missing Authorization