CRITICAL
9.1 CVE-2026-86190 Published 5 Sept 2026
AVideo Unauthenticated User Data Exposure
Worried this affects one of your servers?
AVideo, a video sharing platform, is affected by a broken access control vulnerability.
Unauthenticated users can access complete user records, including password hashes, recovery tokens, and live session identifiers, by providing a specific hash parameter in videoViewsInfo endpoints.
This allows attackers to hijack viewer sessions, including administrator accounts, and obtain sensitive personal data for all video viewers.
Reference: CVE-2026-86190 on NVD
← Back to Security News