SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-81732

MEDIUM · CVSS 6.9 EPSS 0.40% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-28 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

AVideo versions prior to 30.0 are vulnerable due to a lack of authentication on the report4.json.php and report4.1.json.php endpoints, enabling unauthorized access to sensitive user registration statistics. This vulnerability allows attackers to exploit the system by sending GET requests to obtain daily and cumulative registration data without needing any authentication. Organizations using AVideo should prioritize patching this issue to protect user data and maintain compliance with privacy regulations.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-81732
Severity
MEDIUM
CVSS
6.9
EPSS
0.40%

Original NVD Description

WWBN AVideo through version 30.0 fails to enforce authentication on the report4.json.php and report4.1.json.php endpoints, allowing unauthenticated access to user registration statistics. Attackers can send GET requests to these endpoints to retrieve daily and cumulative user-registration counts without any session or authorization.