Missing Authorization in AVideo - CVE-2026-34395

 

Missing Authorization in AVideo - CVE-2026-34395

Published: April 8, 2026


Vulnerability identifier: #VU125490
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2026-34395
CWE-ID: CWE-862
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: World Wide Broadcast Network
Affected software:
AVideo

Detailed vulnerability description

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to missing authorization in plugin/YPTWallet/view/users.json.php when handling requests to the users.json.php endpoint. A remote user can send a request to retrieve all platform users' personal information and wallet balances to disclose sensitive information.

The endpoint is accessible to any authenticated user and exposes data for all users, including admin accounts.


How to mitigate CVE-2026-34395

Install security update from vendor's website.

Sources