Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-85154: AVideo lets stolen video token hijack admin account
CVE-2026-85154 · published today
Summary
The AVideo platform uses a video token that never expires and cannot be revoked. If someone obtains this token, they can log in as the video owner and gain full control, even after the owner changes their password. Disable or replace the token feature and require fresh authentication for all users.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| wwbn | avideo | <= 29.0 |
Original advisory text
WWBN AVideo Authentication Bypass via Non-Expiring video_id_hash
WWBN AVideo contains an authentication failure vulnerability where the video_id_hash credential is a non-expiring, non-revocable bearer token that grants full administrator session access to the video owner's account. Attackers who obtain a video_id_hash can replay it indefinitely to authenticate as the video owner with full privileges, and the credential remains valid even after the owner changes their password.
References
Severity
9.8
Critical
CVSS 3.1: 9.8 (MITRE)
Type
CWE-269Improper Privilege Management
Timeline
Published3 Sep 2026
Updated3 Sep 2026
First seen3 Sep 2026
Monitor software like this
Free during beta