---
id: CVE-2026-85156
title: >-
  WWBN AVideo fails to properly validate access controls on the public channel
  page, allowing unauthenticated visitors to view unlisted and group-restricted
  videos through hardcoded visibility flags and an undefined property
summary: >-
  WWBN AVideo fails to properly validate access controls on the public channel
  page, allowing unauthenticated visitors to view unlisted and group-restricted
  videos through hardcoded visibility flags and an undefined property. Attackers
  can…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-200
published: '2026-09-03'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T20:18:59.270'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-85156'
references:
  - url: 'https://github.com/WWBN/AVideo/security/advisories/GHSA-h779-9wfc-c6m8'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/wwbn-avideo-broken-access-control-via-channel-page
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.00343
epssPercentile: 0.25009
ingestedAt: '2026-09-08T21:11:12.290Z'
---

## Overview

WWBN AVideo fails to properly validate access controls on the public channel page, allowing unauthenticated visitors to view unlisted and group-restricted videos through hardcoded visibility flags and an undefined property. Attackers can access the channel endpoint to retrieve sensitive video content that should be hidden, including full URLs to unlisted videos and thumbnails of member-only content, regardless of the operator's hidePrivateVideos setting.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
