Skip to content
CVE Alert: CVE-2026-86722 – WWBN

CVE Alert: CVE-2026-86722 – WWBN

Redpacketsecurity admin September 9, 2026

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains an authentication bypass vulnerability where sqlDAL caches empty result sets that writeSql never invalidates. Attackers with a valid password can bypass email two-factor authentication on new devices because the confirmation code hash fails to generate from the stale cached empty result.

## AI Summary Analysis

**Risk verdict:** High risk and suitable for urgent remediation where internet-facing instances permit new-device sign-in; KEV, SSVC exploitation status and EPSS are not supplied, so exploitation priority cannot be fully calibrated.

**Why this matters:** A threat actor who obtains a legitimate password may defeat an additional authentication control, turning a stolen low-privilege credential into access to private media, user data and account-management functions. Likely objectives include account takeover, content manipulation, data theft and establishing a foothold for credential reuse elsewhere.

**Most likely attack path:** The attack is network-reachable (AV:N), requires low effort (AC:L), no user interaction (UI:N), and only low privileges (PR:L)—in practice, a valid password—before the additional verification step is reached. Scope is unchanged, so direct impact is concentrated within the application, although reused credentials or administrative access could enable wider compromise.

**Who is most exposed:** Internet-facing, self-hosted video or media platforms with email-based two-factor authentication for unfamiliar devices are the clearest targets. Risk increases where login endpoints are broadly exposed, accounts are shared, or privileged users authenticate from unmanaged systems.

Alert on successful new-device logins without a corresponding valid second-factor event.

Review authentication logs for repeated confirmation-code failures followed by access.

Hunt for unusual downloads, playlist changes, uploads or administrative actions after such logins.

Correlate source IP, device fingerprint and user-agent changes around account access.

Mitigation and prioritisation:

Apply the vendor’s security fix promptly; confirm the deployed build contains the corrected authentication-cache behaviour.

Treat as priority 1 if KEV is true or EPSS is at least 0.5; obtain those missing ratings immediately.

Temporarily restrict administrative access and new-device authentication by VPN, allow-list or identity-aware proxy.

Force reauthentication and rotate exposed passwords, prioritising privileged and reused credentials.

Test the change in staging, preserving MFA telemetry and rollback procedures.

A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.

If you like the site, please support us on Patreon or Buy Me A Coffee using the buttons below.

Extracted Entities

Attack Types (1)

MITRE ATT&CK (1)

Platforms (1)