---
id: CVE-2026-85154
title: >-
  WWBN AVideo contains an authentication failure vulnerability where the
  video_id_hash credential is a non-expiring, non-revocable bearer token that
  grants full administrator session access to the video owner's account
summary: >-
  WWBN AVideo contains an authentication failure vulnerability where the
  video_id_hash credential is a non-expiring, non-revocable bearer token that
  grants full administrator session access to the video owner's account.
  Attackers who obtai…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-269
published: '2026-09-03'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T20:18:59.270'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-85154'
references:
  - url: 'https://github.com/WWBN/AVideo/security/advisories/GHSA-59p8-6m2v-gcr5'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/wwbn-avideo-authentication-bypass-via-non-expiring-video-id-hash
    label: disclosure@vulncheck.com
  - url: 'https://github.com/WWBN/AVideo/security/advisories/GHSA-59p8-6m2v-gcr5'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.00345
epssPercentile: 0.28195
ingestedAt: '2026-09-05T20:44:36.023Z'
---

## Overview

WWBN AVideo contains an authentication failure vulnerability where the video_id_hash credential is a non-expiring, non-revocable bearer token that grants full administrator session access to the video owner's account. Attackers who obtain a video_id_hash can replay it indefinitely to authenticate as the video owner with full privileges, and the credential remains valid even after the owner changes their password.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
