In AVideo through 29.0, the API get_api_video endpoint contains a broken access control vulnerability in the clean_title branch that returns user-group-restricted videos with owner PII to anonymous callers. Attackers can query videos by their public slug to bypass group restrictions and retrieve sensitive user fields including email, phone, address, birth date, and administrator status.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 16 Sep 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In AVideo through 29.0, the API get_api_video endpoint contains a broken access control vulnerability in the clean_title branch that returns user-group-restricted videos with owner PII to anonymous callers. Attackers can query videos by their public slug to bypass group restrictions and retrieve sensitive user fields including email, phone, address, birth date, and administrator status. | |
| Title | AVideo through 29.0 API get_api_video Broken Access Control via clean_title | |
| First Time appeared |
Wwbn
Wwbn avideo |
|
| Weaknesses | CWE-639 | |
| CPEs | cpe:2.3:a:wwbn:avideo:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Wwbn
Wwbn avideo |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-16T21:46:46.351Z
Reserved: 2026-09-16T13:47:20.117Z
Link: CVE-2026-92577
No data.
Status : Received
Published: 2026-09-16T22:18:27.910
Modified: 2026-09-16T22:18:27.910
Link: CVE-2026-92577
No data.
OpenCVE Enrichment
No data.
Weaknesses