Junglewise Threat Intelligence

CVE-2026-90537: WWBN AVideo missing authorization in Scheduler sendEmail

CVE-2026-90537 · Severity: high · CVSS 8.2 · Published 2026-09-12

Technologies: WWBN AVideo. Vendors: WWBN.

Executive brief

WWBN AVideo is a video hosting and streaming platform used to manage and publish live video content and scheduled broadcasts. A missing authorization vulnerability in the Scheduler email plugin allows unauthenticated attackers to enumerate scheduler jobs, read private streamer titles and email addresses, and trigger email messages by simply obtaining a daily token available from any public live streaming page. This exposes sensitive email addresses and live content information to unauthorized access.

Technical details

The vulnerability is a missing authorization check (CWE-862) in plugin/Scheduler/sendEmail.json.php. The endpoint accepts only a site-wide daily token from getToken() which is user-agnostic and valid for 24 hours, then loads and processes any scheduler email job without verifying the requester's identity or permissions. An attacker can obtain this token from any public Live page, then abuse the sendEmail endpoint to enumerate scheduler jobs, read sensitive parameters (email addresses, live titles), and invoke sendSiteEmail to trigger arbitrary email delivery. The vulnerability requires no authentication, network reachability only, and allows high confidentiality impact (email address and live title disclosure) with low integrity impact (email sending). No patch was available at time of reporting.

Affected products

  • WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1

Timeline

  • 2026-09-12: disclosed: Published on NVD and GitHub Security Advisory GHSA-qq59-3jwp-hgj9

References

Related threats