Executive brief
AVideo is a video hosting platform that supports PGP-based two-factor authentication as a security mechanism for user accounts. This vulnerability allows attackers who know a user's password to completely bypass the second-factor protection by submitting an empty request to a verification endpoint, gaining full authenticated access to the account without needing the user's private key. The impact is complete account compromise for any user with PGP two-factor enabled.
Technical details
The vulnerability is an improper authentication flaw (CWE-287) in the LoginControl::verifyChallenge() method, which uses a loose PHP equality operator (==) instead of strict comparison (===) when validating the PGP challenge response. When a session challenge is never populated (because the challenge page is not loaded before calling verifyChallenge.json.php), both the submitted response and the session value are NULL; under loose comparison, NULL == NULL evaluates to true, incorrectly marking the second factor as complete. The vulnerability requires the attacker to have a valid password for a target account that has PGP two-factor enabled, and the attack is performed via a network request with no user interaction required. No patch has been released as of the advisory publication date.
Affected products
- WWBN AVideo through c3edcc274c389816d434acadac07ee78eaf330c1 (including 29.0)
Timeline
- 2026-08-24: disclosed: GitHub Security Advisory GHSA-vmpj-f3mf-q4j2 published
- 2026-09-08: advisory: CVE-2026-86723 assigned