CVE-2026-92586 Details
Description
AVideo through 29.0 (commit c3edcc274c389816d434acadac07ee78eaf330c1) fails to verify video access permissions in the set_api_comment function, allowing authenticated users to post comments on password-protected and group-restricted videos. Attackers can submit POST requests to the comment API endpoint with arbitrary video IDs to write comments on videos they cannot watch.
A vulnerability exists in AVideo versions through 29.0 (up to commit c3edcc274c389816d434acadac07ee78eaf330c1), where the application fails to properly verify video access permissions in the 'set_api_comment' function. This oversight allows authenticated users to post comments on videos that are password-protected or restricted to specific groups. Exploitation involves sending POST requests to the comment API endpoint with chosen video IDs, enabling comments to be added to videos that the user is not permitted to view.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 16, 2026CISA-ADP
Assessed Sep 17, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/WWBN/AVideo/security/advisories/GHSA-fm4f-q895-8jhc | CISA-ADP | AdvisoryExploitTechnical DescriptionVendor |
| https://github.com/WWBN/AVideo/security/advisories/GHSA-fm4f-q895-8jhc | [email protected] | AdvisoryExploitTechnical DescriptionVendor |
| https://www.vulncheck.com/advisories/avideo-through-29.0-missing-authorization-via-comment-api-endpoint | [email protected] | Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-862 | Missing Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| WWBN AVideo | <= c3edcc274c389816d434acadac07ee78eaf330c1 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 17, 2026 | CVE Modified | CISA-ADP |
| Sep 16, 2026 | New CVE Received | [email protected] |
Volerion