CVE-2026-85154
WWBN AVideo contains an authentication failure vulnerability where the videoidhash credential is a non-expiring, non-revocable bearer token that grants full administrator session access to the video owner's account. Attackers who obtain a videoidhash can replay it indefinitely to authenticate as the video owner with full privileges, and the credential remains valid even after the owner changes their password.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/85xxx/CVE-2026-85154.json, https://github.com/WWBN/AVideo/security/advisories/GHSA-59p8-6m2v-gcr5, https://nvd.nist.gov/vuln/detail/CVE-2026-85154, https://www.vulncheck.com/advisories/wwbn-avideo-authentication-bypass-via-non-expiring-video-id-hash