Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.2
CVE-2026-92578: AVideo lets anyone log in with a password hash
CVE-2026-92578 · published 12 days ago
Summary
AVideo stores password hashes in a way that, if someone obtains those hashes, they can use them to sign in as any user without knowing the actual passwords. This means an attacker who accesses the database could take over accounts instantly. Apply the latest AVideo update and reset all user passwords while protecting the database from unauthorized access.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| wwbn | avideo | <= 29.0 |
Original advisory text
WWBN AVideo through 29.0 Authentication Bypass via Stored Password Hash
WWBN AVideo through 29.0 contains an authentication bypass vulnerability where the stored password hash is accepted as a valid login credential through two independent code paths in loginFromRequest() and encryptPasswordVerify(). Attackers who obtain the stored users.password hash value can authenticate as any user by submitting the hash directly to login endpoints, completely bypassing password verification.
References
- https://github.com/WWBN/AVideo/security/advisories/GHSA-fq38-jp6c-q4cx
- https://www.vulncheck.com/advisories/wwbn-avideo-through-29.0-authentication-byp...
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/92xxx/CVE-2026-92578... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-92578 Vendor Advisory
Severity
9.2
Critical
CVSS 3.1: 8.1 (MITRE)
Exploitation
EPSS <1%
Type
CWE-287Improper Authentication
Timeline
Published16 Sep 2026
Updated29 Sep 2026
First seen16 Sep 2026
Track software like this
Free during beta