Junglewise Threat Intelligence

CVE-2026-86723: AVideo LoginControl authentication bypass in PGP two-factor verification

CVE-2026-86723 · Severity: high · CVSS 8.1 · Published 2026-09-08

Technologies: WWBN AVideo. Vendors: WWBN.

Executive brief

AVideo is a video hosting platform that supports PGP-based two-factor authentication as a security mechanism for user accounts. This vulnerability allows attackers who know a user's password to completely bypass the second-factor protection by submitting an empty request to a verification endpoint, gaining full authenticated access to the account without needing the user's private key. The impact is complete account compromise for any user with PGP two-factor enabled.

Technical details

The vulnerability is an improper authentication flaw (CWE-287) in the LoginControl::verifyChallenge() method, which uses a loose PHP equality operator (==) instead of strict comparison (===) when validating the PGP challenge response. When a session challenge is never populated (because the challenge page is not loaded before calling verifyChallenge.json.php), both the submitted response and the session value are NULL; under loose comparison, NULL == NULL evaluates to true, incorrectly marking the second factor as complete. The vulnerability requires the attacker to have a valid password for a target account that has PGP two-factor enabled, and the attack is performed via a network request with no user interaction required. No patch has been released as of the advisory publication date.

Affected products

  • WWBN AVideo through c3edcc274c389816d434acadac07ee78eaf330c1 (including 29.0)

Timeline

  • 2026-08-24: disclosed: GitHub Security Advisory GHSA-vmpj-f3mf-q4j2 published
  • 2026-09-08: advisory: CVE-2026-86723 assigned

References

Related threats