---
id: CVE-2026-90548
title: >-
  WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to
  validate user permissions in the ImageGallery list.json.php endpoint, allowing
  unauthenticated access to list gallery files
summary: >-
  WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to
  validate user permissions in the ImageGallery list.json.php endpoint, allowing
  unauthenticated access to list gallery files. Attackers can retrieve filenames
  an…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-200
vendor: WWBN
product: AVideo
affected:
  - AVideo <= c3edcc274c389816d434acadac07ee78eaf330c1
published: '2026-09-12'
updated: '2026-09-14'
sourceUpdated: '2026-09-14T21:07:11.883'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-90548'
references:
  - url: 'https://github.com/WWBN/AVideo/security/advisories/GHSA-vr35-39vf-9qp9'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/wwbn-avideo-missing-authorization-in-imagegallery-list-json-php
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
  - exploit-available
epss: 0.00396
epssPercentile: 0.30993
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-14T18:26:23.247545Z'
ingestedAt: '2026-09-14T15:23:07.479Z'
---

## Overview

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate user permissions in the ImageGallery list.json.php endpoint, allowing unauthenticated access to list gallery files. Attackers can retrieve filenames and URLs of password-protected image galleries by directly accessing the endpoint, then fetch the exposed files without authentication.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
