Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 08 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 08 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | AVideo through c3edcc274c389816d434acadac07ee78eaf330c1 contains an authentication bypass vulnerability in LoginControl::verifyChallenge() that uses loose comparison (==) instead of strict comparison (===) against unset session values. Attackers with only a password can submit an empty request to verifyChallenge.json.php to bypass PGP two-factor authentication and gain full authenticated access. | |
| Title | AVideo LoginControl PGP Authentication Bypass via verifyChallenge | |
| First Time appeared |
Wwbn
Wwbn avideo |
|
| Weaknesses | CWE-287 | |
| CPEs | cpe:2.3:a:wwbn:avideo:-:*:*:*:*:*:*:* | |
| Vendors & Products |
Wwbn
Wwbn avideo |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-08T15:34:32.680Z
Reserved: 2026-09-08T11:30:41.420Z
Link: CVE-2026-86723
Updated: 2026-09-08T15:34:26.001Z
Status : Received
Published: 2026-09-08T16:18:32.583
Modified: 2026-09-08T16:18:32.583
Link: CVE-2026-86723
No data.
OpenCVE Enrichment
Updated: 2026-09-08T16:30:07Z
-
CWE-287
Improper Authentication