SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-86729

HIGH · CVSS 7.4 EPSS 0.22% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-08 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The vulnerability in Oracle's AVideo allows attackers to exploit an undocumented login endpoint, enabling unlimited password guessing attempts without any rate limiting. This flaw not only facilitates brute-force attacks on user accounts, including admin accounts, but also reveals user identities through its response messages, effectively acting as a credential oracle. Organizations using AVideo should prioritize immediate remediation to protect against potential account takeovers.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-86729
Severity
HIGH
CVSS
7.4
EPSS
0.22%
Oracle

Original NVD Description

WWBN AVideo through commit e01e41ecc (no patched version available) exposes get_api_preauthorize in plugin/API/API.php as a second, undocumented login path. Unlike get_api_signIn, which enforces a rate limit of 10 attempts per 5 minutes via checkRateLimit(), get_api_preauthorize performs the same credential check with no throttling for any client, allowing unlimited remote password guessing against arbitrary accounts, including admin. The endpoint also acts as a credential oracle: it returns the message "Invalid credentials" for both correct and incorrect passwords, while the users_id field in the response body discloses the authenticated identity (users_id:1 on success, users_id:0 on failure), and a correct password establishes a session cookie that remains usable for authenticated API requests. Together these issues permit unauthenticated brute-force account takeover.