PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-88866 WWBN CVE debrief

AVideo's LoginControl plugin contains a stored cross-site scripting vulnerability. Attackers with valid login accounts can inject malicious scripts in the User-Agent header, executing in administrator browsers when viewing the Login History page. This vulnerability requires verification of affected versions and exposure, and mitigation is crucial to prevent unauthorized actions and potential privilege escalation. The vulnerability affects AVideo installations, particularly if administrators view login history or if users with valid accounts can be tricked into injecting malicious scripts.

Vendor
WWBN
Product
AVideo
CVSS
CRITICAL 9.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-10
Original CVE updated
2026-09-15
Advisory published
2026-09-10
Advisory updated
2026-09-15

Who should care

Administrators and defenders of AVideo installations should assess exposure and prioritize mitigation, especially if administrators view login history or if users with valid accounts can be tricked into injecting malicious scripts.

Why it matters

Defenders should care about CVE-2026-88866 because it allows attackers to inject malicious scripts in the User-Agent header, potentially leading to script execution within administrator sessions. This vulnerability requires verification of affected versions and exposure, and mitigation is crucial to prevent unauthorized actions and potential privilege escalation.

  • Script execution within administrator sessions
  • Potential for unauthorized actions within the administrator session
  • Possible theft of sensitive information or escalation of privileges
  • Requires verification of affected versions and exposure

Technical summary

The AVideo LoginControl plugin fails to encode the User-Agent header before storing it in login history, allowing attackers with valid login accounts to inject malicious scripts that execute in administrator browsers when viewing the Login History page. This vulnerability requires verification of affected AVideo versions and exposure, and mitigation is crucial to prevent unauthorized actions and potential privilege escalation. The vulnerability affects AVideo installations, particularly if administrators view login history or if users with valid accounts can be tricked into injecting malicious scripts.

Defensive priority

Defenders should prioritize verifying and mitigating this vulnerability, especially for administrators who view login history.

Recommended defensive actions

  • Verify the vulnerability exists in your AVideo installation
  • Restrict access to the Login History page for non-administrative users
  • Implement additional security measures to monitor and filter User-Agent headers
  • Update the LoginControl plugin to a version that encodes the User-Agent header
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record and NVD entry provide details on the vulnerability. However, the vendor and affected versions are not clearly identified, requiring further verification. The vulnerability exists in AVideo's LoginControl plugin, which fails to encode the User-Agent header before storing it in login history. This allows attackers with valid login accounts to inject malicious scripts that execute in administrator browsers when viewing the Login History page. Defenders should verify the existence of affected AVideo installations and assess

Sources and references

Verified primary and authoritative sources

  • CVE-2026-88866 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-88866

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-88866 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-88866

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.