THREAT OPS › Threat News › [NVD] CVE-2026-59256 (HIGH 7.5) — WWBN AVideo through commit 9c39d8c8 contains an authorization bypass vulnerability where getToken() creates tokens without binding to user identity or purpose, and plugin/Gallery/view/sections.php issues valid tokens to unauthenticated visitors. Attackers can retrieve a token fro
[NVD] CVE-2026-59256 (HIGH 7.5) — WWBN AVideo through commit 9c39d8c8 contains an authorization bypass vulnerability where getToken() creates tokens without binding to user identity or purpose, and plugin/Gallery/view/sections.php issues valid tokens to unauthenticated visitors. Attackers can retrieve a token fro
CVE-2026-59256 CVSS: 7.5 HIGH Published: 2026-08-22T13:16:38.817
WWBN AVideo through commit 9c39d8c8 contains an authorization bypass vulnerability where getToken() creates tokens without binding to user identity or purpose, and plugin/Gallery/view/sections.php issues valid tokens to unauthenticated visitors. Attackers can retrieve a token from the Gallery endpoint and use it to bypass authorizat
Indicators of compromise
- CVE-2026-59256cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-59256