Junglewise Threat Intelligence

CVE-2026-89251: AVideo missing authorization in AD_Server log.php wallet credit

CVE-2026-89251 · Severity: medium · CVSS 6.5 · Published 2026-09-11

Technologies: WWBN AVideo. Vendors: WWBN.

Executive brief

AVideo is a video sharing platform with an integrated ad server and wallet system that allows campaign owners to earn credits when ads are displayed. The vulnerability allows any logged-in user to repeatedly submit fake ad impression records and fraudulently inflate the wallet balance of campaign video owners without any proof that an ad actually played. This enables attackers to steal video credits that can be converted to real payments or transferred.

Technical details

The vulnerability is a missing authorization (CWE-862) and insufficient data authenticity verification (CWE-345) in plugin/AD_Server/log.php. The endpoint accepts client-controlled label parameters directly from $_REQUEST without validating that an ad impression actually occurred, and passes them to VastCampaignsLogs::save() which automatically calls reward() when label equals 'start', crediting the campaign video owner's YPTWallet. The attack requires only that the attacker be authenticated; no CSRF protection exists because the file is not a .json.php endpoint. An attacker can repeatedly POST label=start requests with a campaign_has_videos_id to mint arbitrary YPTWallet credits, with no proof of ad playback, campaign validity, or that the attacker is not the beneficiary. No patch has been released as of the advisory publication date.

Affected products

  • WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1

Timeline

  • 2026-08-27: disclosed: GitHub Security Advisory GHSA-cwrf-q9jv-44px published
  • 2026-09-11: advisory: CVE-2026-89251 published on NVD

References

Related threats