THREAT OPS › Threat News › [NVD] CVE-2026-90538 (MEDIUM 5.3) — WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in playlistsFromUser.json.php that allows unauthenticated attackers to read private playlists by requesting another user's identifier. Attackers can retrieve Favorit
[NVD] CVE-2026-90538 (MEDIUM 5.3) — WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in playlistsFromUser.json.php that allows unauthenticated attackers to read private playlists by requesting another user's identifier. Attackers can retrieve Favorit
CVE-2026-90538 CVSS: 5.3 MEDIUM Published: 2026-09-12T13:16:51.807
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in playlistsFromUser.json.php that allows unauthenticated attackers to read private playlists by requesting another user's identifier. Attackers can retrieve Favorite and Watch Later playlists belonging to other users
Indicators of compromise
- c3edcc274c389816d434acadac07ee78eaf330c1sha1
- CVE-2026-90538cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-90538