CRITICAL 9.8 CVE-2026-85154 Published 3 Sept 2026

AVideo Auth Bypass via Persistent Video ID Hash

Worried this affects one of your servers?

WWBN AVideo, a video sharing platform, is affected by an authentication bypass vulnerability.

AVideo uses a non-expiring, non-revocable bearer token named video_id_hash for authentication. An attacker obtaining this token can use it indefinitely to gain full administrator access to the video owner's account, even after the owner changes their password.

Reference: CVE-2026-85154 on NVD

← Back to Security News