Junglewise Threat Intelligence

CVE-2026-90547: WWBN AVideo missing authorization in Bookmark plugin

CVE-2026-90547 · Severity: medium · CVSS 5.3 · Published 2026-09-12

Technologies: WWBN AVideo. Vendors: WWBN.

Executive brief

WWBN AVideo is a self-hosted video streaming platform. The Bookmark plugin endpoint fails to validate user permissions, allowing unauthenticated attackers to retrieve chapter metadata (chapter names and timestamps) from password-protected videos. This leaks sensitive content structure information that should only be accessible to authorized viewers.

Technical details

The Bookmark plugin endpoint `getBookmarks.json.php` instantiates a Video object and retrieves bookmarks via `BookmarkTable::getAllFromVideo()` without calling `User::canWatchVideo()` to verify the requester's permission to access the video. The vulnerability is a missing authorization check (CWE-862, CWE-200) in an unauthenticated, network-accessible endpoint. An attacker can craft a GET request with a `videos_id` parameter pointing to any password-protected video and receive the full chapter metadata in JSON format. No authentication, password validation, or user interaction is required. Fix status: unfixed at time of advisory publication (Aug 28, 2026).

Affected products

  • WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1

Timeline

  • 2026-08-28: disclosed
  • 2026-09-12: advisory

References

Related threats