External risk intelligence

WWBN AVideo Broken Access Control Exposes User Records and Session Identifiers.

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-86190

AVideo is a web-based video platform designed to be publicly accessible for streaming content. The vulnerable endpoint is part of the application's core functionality, which is intended to be reachable by internet users, making the attack surface public-facing by design.

Information Disclosure

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A security vulnerability in WWBN AVideo allows unauthenticated access to sensitive user data, including password hashes and session identifiers. This could enable attackers to hijack user sessions and access personal information.

  • Unauthenticated users can access sensitive user records.
  • Session hijacking and sensitive data access are possible.
  • Confirm relevance and exposure for this video platform.

Attack Path

How an attacker could exploit the issue

An attacker can exploit a flaw in how video viewing information is handled to access sensitive user data. By sending a request with a specific parameter, an unauthenticated attacker can retrieve complete user records, including password hashes and active session details. This access can then be leveraged to hijack viewer sessions, even those belonging to administrators, and to steal personal data from all users.

  • No authentication is required to access the endpoint.
  • A specially crafted request to the videoViewsInfo endpoint triggers the vulnerability.
  • Allows session hijacking and theft of sensitive user data.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could expose complete user records, including password hashes, recovery tokens, and live session identifiers, to unauthenticated callers. When a hash parameter is provided to the videoViewsInfo endpoints, this sensitive information can be disclosed.

  • User records and session identifiers at risk.
  • Disclosed via vulnerable videoViewsInfo endpoints.
  • Facilitates session hijacking and data theft.

Operational Fix

Recommended remediation, mitigation, and detection steps

The broken access control vulnerability in WWBN AVideo's videoViewsInfo endpoints presents a critical risk, as it exposes sensitive user data and session identifiers to unauthenticated callers. The platform team, responsible for AVideo's infrastructure, should lead the response by first identifying all instances of AVideo within the environment and confirming their internet accessibility and business criticality. Subsequently, they must identify the accountable application or system owner for each instance to initiate a coordinated remediation plan based on the assessed risk.

  • Platform team owns the issue.
  • Verify AVideo exposure and criticality.
  • Plan remediation based on risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is WWBN AVideo?

WWBN AVideo is an open-source, web-based video streaming platform. It allows users to build their own video hosting sites, similar to self-hosted versions of popular streaming services. Because it is designed for content delivery, it typically functions as a web application that stores user accounts, viewer logs, and session information to manage streaming access and administrative controls.

What is the broken access control issue in CVE-2026-86190?

This vulnerability is classified as CWE-200, which involves the exposure of sensitive information. In simple terms, the application fails to verify if a user has permission to see certain data. Because of this flaw, the system mistakenly grants unauthenticated visitors access to private database records, including password hashes and active session identifiers, which should only be visible to specific users or administrators.

How is this vulnerability triggered?

An attacker triggers this flaw by sending a network request to the specific 'videoViewsInfo' endpoint within the software. The vulnerability becomes active when the request includes a 'hash' parameter. It is important to note that no prior login or account is required; the software incorrectly processes the request and returns the sensitive data even if the sender has no authorization.

Do I need to worry if my AVideo instance is internal?

Halo Surface Signal indicates that AVideo is typically designed to be publicly accessible for streaming, which creates a broad attack surface. If your instance is exposed to the internet, it is at higher risk. Even if hosted internally, any user or device with network access to the application can reach the vulnerable endpoint, making it important to evaluate your deployment's visibility.

What should I do if I am running AVideo?

Start by identifying all AVideo installations in your environment and confirming if they are reachable over the network. Determine who is responsible for managing each instance to ensure clear accountability. Once located, verify the business criticality of those systems to help prioritize your response. Consult the vendor's security guidance to understand the recommended updates or configuration changes needed to secure the affected endpoints.

References