CVE-2026-92578

WWBN AVideo through 29.0 contains an authentication bypass vulnerability where the stored password hash is accepted as a valid login credential through two independent code paths in loginFromRequest() and encryptPasswordVerify(). Attackers who obtain the stored users.password hash value can authenticate as any user by submitting the hash directly to login endpoints, completely bypassing password verification.
Configurations

No configuration.

History

17 Sep 2026, 15:16

Type Values Removed Values Added
References () https://github.com/WWBN/AVideo/security/advisories/GHSA-fq38-jp6c-q4cx - () https://github.com/WWBN/AVideo/security/advisories/GHSA-fq38-jp6c-q4cx -

16 Sep 2026, 22:18

Type Values Removed Values Added
New CVE

Information

Published : 2026-09-16 22:18

Updated : 2026-09-17 15:16


NVD link : CVE-2026-92578

Mitre link : CVE-2026-92578

CVE.ORG link : CVE-2026-92578


JSON object : View

Products Affected

No product.

CWE
CWE-287

Improper Authentication