---
id: CVE-2026-90552
title: >-
  WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to
  validate playlist ownership in the Playlists_schedules/list.json.php and
  Live/calendar.json.php endpoints, allowing authenticated and unauthenticated
  users to r…
summary: >-
  WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to
  validate playlist ownership in the Playlists_schedules/list.json.php and
  Live/calendar.json.php endpoints, allowing authenticated and unauthenticated
  users to r…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-639
vendor: WWBN
product: AVideo
affected:
  - AVideo <= c3edcc274c389816d434acadac07ee78eaf330c1
published: '2026-09-12'
updated: '2026-09-15'
sourceUpdated: '2026-09-15T18:19:36.947'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-90552'
references:
  - url: 'https://github.com/WWBN/AVideo/security/advisories/GHSA-f4q2-49rm-rxh7'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/wwbn-avideo-missing-authorization-via-playlists-schedules-list-json-php
    label: disclosure@vulncheck.com
  - url: 'https://github.com/WWBN/AVideo/security/advisories/GHSA-f4q2-49rm-rxh7'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
epss: 0.00357
epssPercentile: 0.26756
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-15T17:05:42.800503Z'
ingestedAt: '2026-09-14T15:23:07.479Z'
---

## Overview

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate playlist ownership in the Playlists_schedules/list.json.php and Live/calendar.json.php endpoints, allowing authenticated and unauthenticated users to read private playlist schedule metadata. Attackers with canStream privileges or no authentication can retrieve schedule names, descriptions, timestamps, and playlist identifiers by querying these endpoints without ownership checks.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
