Executive brief
WWBN AVideo is a self-hosted video platform that manages user playlists. An authentication bypass flaw allows unauthenticated visitors to retrieve other users' private playlists (Favorite and Watch Later lists) through improper caching logic. This results in unauthorized disclosure of personal viewing and preference data.
Technical details
The vulnerability is a missing authorization flaw (CWE-862, CWE-200) in objects/playlistsFromUser.json.php. The endpoint checks if a caller is authenticated before allowing access to private playlists; however, the PlayListUserCacheHandler uses only the user ID as a cache key, not accounting for the publicOnly flag or the requester's authentication state. When an authenticated user accesses another user's playlists, their private rows (status=favorite or watch_later) are cached and later served to unauthenticated guests requesting that user's ID. No authentication or privilege is required; exploitation requires only crafting HTTP requests with different user IDs. An attacker gains read access to another user's sensitive playlist data, including viewing history and favorites. Patches were not available at the time of reporting (commit c3edcc274c389816c434acadac07ee78eaf330c1 remains vulnerable).
Affected products
- WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1
Timeline
- 2026-08-28: disclosed: GitHub Security Advisory GHSA-6382-hm4f-hxqg published
- 2026-09-12: advisory: CVE-2026-90538 published on NVD