Junglewise Threat Intelligence

CVE-2026-90541: WWBN AVideo missing authentication in TopMenu endpoint

CVE-2026-90541 · Severity: medium · CVSS 5.3 · Published 2026-09-12

Technologies: WWBN AVideo. Vendors: WWBN.

Executive brief

WWBN AVideo is a video streaming and management platform. The TopMenu plugin endpoint fails to require authentication, allowing anyone on the network to retrieve sensitive menu configuration data including inactive and admin-only menus that should only be visible to authorized administrators. This information disclosure could help attackers map the system's internal structure and identify hidden administrative features.

Technical details

The vulnerability is a missing authentication issue (CWE-306) in the plugin/TopMenu/menus.json.php endpoint. The endpoint calls Menu::getAll() without requiring User::isAdmin() authentication, whereas the related menuSave.json.php correctly enforces admin authentication. An unauthenticated attacker can send a GET request to this endpoint over the network to retrieve all menu records as JSON, including inactive menus and admin-only entries. No user interaction or special privileges are required for exploitation. At the time of reporting, no patch was available; the vulnerability exists through at least commit c3edcc274c389816d434acadac07ee78eaf330c1.

Affected products

  • WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1

Timeline

  • 2026-08-28: disclosed
  • 2026-09-12: advisory

References

Related threats