---
id: CVE-2026-90542
title: >-
  WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to
  validate that logged-in users can access live schedules before creating
  reminders via remindMe.json.php
summary: >-
  WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to
  validate that logged-in users can access live schedules before creating
  reminders via remindMe.json.php. Authenticated attackers can create scheduler
  reminders …
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'
cwe:
  - CWE-639
vendor: WWBN
product: AVideo
affected:
  - AVideo <= c3edcc274c389816d434acadac07ee78eaf330c1
published: '2026-09-12'
updated: '2026-09-15'
sourceUpdated: '2026-09-15T18:19:36.713'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-90542'
references:
  - url: 'https://github.com/WWBN/AVideo/security/advisories/GHSA-qf26-4xp7-q5h9'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/wwbn-avideo-missing-authorization-via-remindme-json-php
    label: disclosure@vulncheck.com
  - url: 'https://github.com/WWBN/AVideo/security/advisories/GHSA-qf26-4xp7-q5h9'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
epss: 0.00239
epssPercentile: 0.13389
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-15T17:01:46.863865Z'
ingestedAt: '2026-09-14T15:23:07.480Z'
---

## Overview

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate that logged-in users can access live schedules before creating reminders via remindMe.json.php. Authenticated attackers can create scheduler reminders for private live schedules they cannot view and learn the private schedule title from the generated email job.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
