Junglewise Threat Intelligence

CVE-2026-89257: AVideo IDOR in categoryDeleteAssets.json.php

CVE-2026-89257 · Severity: medium · CVSS 5.4 · Published 2026-09-11

Technologies: WWBN AVideo. Vendors: WWBN.

Executive brief

AVideo is a self-hosted video hosting platform. The categoryDeleteAssets endpoint allows authenticated non-admin users to delete any other user's category asset directories (icons and images) by specifying an arbitrary category ID, due to a missing ownership verification check. While category records and videos are preserved, attackers can degrade service availability and alter the appearance of other users' content libraries. This vulnerability only affects installations that have enabled the non-default "usersCanCreateNewCategories" configuration setting.

Technical details

The vulnerability is an insecure direct object reference (IDOR) in objects/categoryDeleteAssets.json.php that fails to validate category ownership before deletion. The endpoint checks only Category::canCreateCategory() (which returns true for non-admin users with canUpload permission when usersCanCreateNewCategories is enabled) and a CSRF token before calling Category::deleteAssets() with an attacker-supplied category ID. The vulnerable code path omits the Category::userCanEditCategory() ownership check that the sibling Category::delete() method properly enforces. An authenticated non-admin with canUpload capability can send a POST request with an arbitrary category ID to recursively delete any category's asset directory ({systemRootPath}videos/categories/assets/{id}/). The attack requires authentication and knowledge of valid category IDs, but no user interaction or additional complexity. As of the advisory publication date, no patched version is available.

Affected products

  • WWBN AVideo through 29.0

Timeline

  • 2026-09-11: disclosed: CVE-2026-89257 published; no patched version available at disclosure
  • 2026-08-27: other: GitHub Security Advisory GHSA-gf2v-r8wx-ghqj published

References

Related threats