Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.2

CVE-2026-92578: AVideo lets anyone log in with a password hash

CVE-2026-92578 · published 12 days ago
Summary

AVideo stores password hashes in a way that, if someone obtains those hashes, they can use them to sign in as any user without knowing the actual passwords. This means an attacker who accesses the database could take over accounts instantly. Apply the latest AVideo update and reset all user passwords while protecting the database from unauthorized access.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
wwbn avideo <= 29.0
Original advisory text
WWBN AVideo through 29.0 Authentication Bypass via Stored Password Hash
WWBN AVideo through 29.0 contains an authentication bypass vulnerability where the stored password hash is accepted as a valid login credential through two independent code paths in loginFromRequest() and encryptPasswordVerify(). Attackers who obtain the stored users.password hash value can authenticate as any user by submitting the hash directly to login endpoints, completely bypassing password verification.
Severity
9.2 Critical
CVSS 3.1: 8.1 (MITRE)
Exploitation
EPSS <1%
Type
CWE-287Improper Authentication
Timeline
Published16 Sep 2026
Updated29 Sep 2026
First seen16 Sep 2026
Sources
CVE-2026-92578 · MITRE
Track software like this
Free during beta