Junglewise Threat Intelligence

CVE-2026-59256: WWBN AVideo authorization bypass in token validation

CVE-2026-59256 · Severity: high · CVSS 7.5 · Published 2026-08-22

Technologies: WWBN AVideo. Vendors: WWBN.

Executive brief

WWBN AVideo is a video content management system. The application generates access tokens that are not tied to any user identity or purpose, and exposes these tokens to unauthenticated visitors through a Gallery feature. An attacker can retrieve a public token and use it to bypass authorization checks to access restricted video content that should only be available to authenticated users.

Technical details

The vulnerability is an insufficient credential protection issue (CWE-565, CWE-863) in the getToken() function, which creates tokens containing only a salt, timezone, optional video ID, and time window—with no user identity, session binding, or nonce. The verifyToken() function skips the video_id comparison when it is 0 (the default in all call sites), rendering that field inert. plugin/Gallery/view/sections.php:12 mints and serves valid tokens to any unauthenticated visitor without authorization checks. An attacker can retrieve a token with a single GET request and use it as a globalToken parameter in view/hls.php to bypass User::canWatchVideo() authorization checks and access restricted video playlists. The Gallery plugin is enabled by default during installation, making the attack surface immediately available. No patches are available as of the advisory date.

Affected products

  • WWBN AVideo through commit 9c39d8c8

Timeline

  • 2026-08-22: disclosed: Published on GitHub and NVD
  • 2026-08-07: advisory: GitHub Security Advisory GHSA-wq57-wxcr-rx6v published

References

Related threats