Skip to main content
CRITICAL

CVE-2026-86190

WWBN AVideo Broken Access Control via videoViewsInfo hash Parameter

CVSS v3

9.1

CRITICAL

EPSS Score

0.4 %

exploit probability, as of 2026-09-28

CISA KEV

No

known exploited

Exploitation

—

SSVC status

Description

WWBN AVideo contains a broken access control vulnerability in videoViewsInfo endpoints that returns complete user records including password hashes, recovery tokens, and live session identifiers to unauthenticated callers when a hash parameter is provided. Attackers can use the disclosed session identifier to hijack viewer sessions, including administrator accounts, and obtain sensitive personal data for all video viewers.

Technical details

Published
2026-09-05
Last Modified
2026-09-05

Frequently asked questions

What is CVE-2026-86190?

WWBN AVideo contains a broken access control vulnerability in videoViewsInfo endpoints that returns complete user records including password hashes, recovery tokens, and live session identifiers to unauthenticated callers when a hash parameter is provided. Attackers can use the disclosed session identifier to hijack viewer sessions, including administrator accounts, and obtain sensitive personal data for all video viewers.

Is CVE-2026-86190 actively exploited?

Active exploitation of CVE-2026-86190 has not been confirmed. Its EPSS score was 0.4% on 2026-09-28, the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2026-86190?

CVE-2026-86190 has a CVSS v3 base score of 9.1 (CRITICAL severity).

Is CVE-2026-86190 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key