#VU125490 Missing Authorization in AVideo - CVE-2026-34395

 

#VU125490 Missing Authorization in AVideo - CVE-2026-34395

Published: April 8, 2026


Vulnerability identifier: #VU125490
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2026-34395
CWE-ID: CWE-862
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
AVideo
Software vendor:
World Wide Broadcast Network

Description

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to missing authorization in plugin/YPTWallet/view/users.json.php when handling requests to the users.json.php endpoint. A remote user can send a request to retrieve all platform users' personal information and wallet balances to disclose sensitive information.

The endpoint is accessible to any authenticated user and exposes data for all users, including admin accounts.


Remediation

Install security update from vendor's website.

External links