CRITICAL 9.8 CVE-2026-84480 Published 1 Sept 2026

AVideo Password Recovery Token Expiration Bypass

Worried this affects one of your servers?

AVideo, a video sharing platform, has a vulnerability in its password recovery process. The script userRecoverPassSave.json.php does not validate the expiration of recovery tokens, allowing attackers to use expired tokens to reset account passwords indefinitely.

An attacker with access to a recovery token can use it at any time to change the target account's password and gain full account access.

Reference: CVE-2026-84480 on NVD

← Back to Security News