CRITICAL
9.8 CVE-2026-85154 Published 3 Sept 2026
AVideo Auth Bypass via Persistent Video ID Hash
Worried this affects one of your servers?
WWBN AVideo, a video sharing platform, is affected by an authentication bypass vulnerability.
AVideo uses a non-expiring, non-revocable bearer token named video_id_hash for authentication. An attacker obtaining this token can use it indefinitely to gain full administrator access to the video owner's account, even after the owner changes their password.
Reference: CVE-2026-85154 on NVD
← Back to Security News