Security Advisory

CVE-2026-85157

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-09-03 11:22:10
Last updated 2026-09-03 12:32:03
Assigner VulnCheck
CVSS score 6.9
State PUBLISHED

Description

WWBN AVideo contains a broken access control vulnerability in the unauthenticated feed/index.php endpoint that disables per-video visibility checks when a program_id parameter is supplied. Attackers can enumerate playlist identifiers and retrieve unlisted and group-restricted videos by requesting the RSS feed with any visible playlist id, including empty playlists that return the entire site's hidden video catalogue.