THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-59256 (HIGH 7.5) — WWBN AVideo through commit 9c39d8c8 contains an authorization bypass vulnerability where getToken() creates tokens without binding to user identity or purpose, and plugin/Gallery/view/sections.php issues valid tokens to unauthenticated visitors. Attackers can retrieve a token fro

[NVD] CVE-2026-59256 (HIGH 7.5) — WWBN AVideo through commit 9c39d8c8 contains an authorization bypass vulnerability where getToken() creates tokens without binding to user identity or purpose, and plugin/Gallery/view/sections.php issues valid tokens to unauthenticated visitors. Attackers can retrieve a token fro

mednvdPublished 2026-08-22

CVE-2026-59256 CVSS: 7.5 HIGH Published: 2026-08-22T13:16:38.817

WWBN AVideo through commit 9c39d8c8 contains an authorization bypass vulnerability where getToken() creates tokens without binding to user identity or purpose, and plugin/Gallery/view/sections.php issues valid tokens to unauthenticated visitors. Attackers can retrieve a token from the Gallery endpoint and use it to bypass authorizat

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-59256