CVE-2026-90549

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to properly authorize access to the videosAndroid.json.php endpoint, allowing unauthenticated guests to list password-protected videos with sensitive owner information. Attackers can retrieve video metadata including owner email, lastLogin, filename, and hashId by sending an unauthenticated GET request to the endpoint.

  • Published Sep 12, 2026
  • CVSS 6.9 medium
  • 0.3% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-90549 at the National Vulnerability Database