CRITICAL 9.1 CVE-2026-86190 Published 5 Sept 2026

AVideo Unauthenticated User Data Exposure

Worried this affects one of your servers?

AVideo, a video sharing platform, is affected by a broken access control vulnerability.

Unauthenticated users can access complete user records, including password hashes, recovery tokens, and live session identifiers, by providing a specific hash parameter in videoViewsInfo endpoints.

This allows attackers to hijack viewer sessions, including administrator accounts, and obtain sensitive personal data for all video viewers.

Reference: CVE-2026-86190 on NVD

← Back to Security News