PatchSiren cyber security CVE debrief
CVE-2026-88866 WWBN CVE debrief
AVideo's LoginControl plugin contains a stored cross-site scripting vulnerability. Attackers with valid login accounts can inject malicious scripts in the User-Agent header, executing in administrator browsers when viewing the Login History page. This vulnerability requires verification of affected versions and exposure, and mitigation is crucial to prevent unauthorized actions and potential privilege escalation. The vulnerability affects AVideo installations, particularly if administrators view login history or if users with valid accounts can be tricked into injecting malicious scripts.
- Vendor
- WWBN
- Product
- AVideo
- CVSS
- CRITICAL 9.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-10
- Original CVE updated
- 2026-09-15
- Advisory published
- 2026-09-10
- Advisory updated
- 2026-09-15
Who should care
Administrators and defenders of AVideo installations should assess exposure and prioritize mitigation, especially if administrators view login history or if users with valid accounts can be tricked into injecting malicious scripts.
Why it matters
Defenders should care about CVE-2026-88866 because it allows attackers to inject malicious scripts in the User-Agent header, potentially leading to script execution within administrator sessions. This vulnerability requires verification of affected versions and exposure, and mitigation is crucial to prevent unauthorized actions and potential privilege escalation.
- Script execution within administrator sessions
- Potential for unauthorized actions within the administrator session
- Possible theft of sensitive information or escalation of privileges
- Requires verification of affected versions and exposure
Technical summary
The AVideo LoginControl plugin fails to encode the User-Agent header before storing it in login history, allowing attackers with valid login accounts to inject malicious scripts that execute in administrator browsers when viewing the Login History page. This vulnerability requires verification of affected AVideo versions and exposure, and mitigation is crucial to prevent unauthorized actions and potential privilege escalation. The vulnerability affects AVideo installations, particularly if administrators view login history or if users with valid accounts can be tricked into injecting malicious scripts.
Defensive priority
Defenders should prioritize verifying and mitigating this vulnerability, especially for administrators who view login history.
Recommended defensive actions
- Verify the vulnerability exists in your AVideo installation
- Restrict access to the Login History page for non-administrative users
- Implement additional security measures to monitor and filter User-Agent headers
- Update the LoginControl plugin to a version that encodes the User-Agent header
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record and NVD entry provide details on the vulnerability. However, the vendor and affected versions are not clearly identified, requiring further verification. The vulnerability exists in AVideo's LoginControl plugin, which fails to encode the User-Agent header before storing it in login history. This allows attackers with valid login accounts to inject malicious scripts that execute in administrator browsers when viewing the Login History page. Defenders should verify the existence of affected AVideo installations and assess
Sources and references
Verified primary and authoritative sources
-
CVE-2026-88866 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-88866
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-88866 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-88866
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/WWBN/AVideo/security/advisories/GHSA-wg67-62q3-2m33
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/wwbn-avideo-logincontrol-stored-xss-via-user-agent-header
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.