{"id":"CVE-2026-85154","aliases":["GHSA-59p8-6m2v-gcr5"],"url":"https://o3.security/vulnerability/CVE-2026-85154","summary":"WWBN AVideo Authentication Bypass via Non-Expiring video_id_hash","details":"WWBN AVideo contains an authentication failure vulnerability where the video_id_hash credential is a non-expiring, non-revocable bearer token that grants full administrator session access to the video owner's account. Attackers who obtain a video_id_hash can replay it indefinitely to authenticate as the video owner with full privileges, and the credential remains valid even after the owner changes their password.","published":"2026-09-03T11:22:08.455Z","modified":"2026-09-04T03:47:29.176261829Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/85xxx/CVE-2026-85154.json"},{"type":"ADVISORY","url":"https://github.com/WWBN/AVideo/security/advisories/GHSA-59p8-6m2v-gcr5"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-85154"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/wwbn-avideo-authentication-bypass-via-non-expiring-video-id-hash"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-04T03:47:29.176261829Z"}}