PatchSiren cyber security CVE debrief
CVE-2026-88870 WWBN CVE debrief
A cross-site request forgery vulnerability exists in the LoginControl plugin PGP key endpoints of WWBN AVideo, allowing attackers to replace a logged-in victim's PGP 2FA public key. This can cause lockout or enable account takeover if the attacker knows the password. The vulnerability is due to a lack of CSRF token validation, and defenders should assess exposure and implement compensating controls to prevent account takeover. AVideo deployments should verify affected versions and implement remediation.
- Vendor
- WWBN
- Product
- AVideo
- CVSS
- HIGH 7.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-10
- Original CVE updated
- 2026-09-18
- Advisory published
- 2026-09-10
- Advisory updated
- 2026-09-18
Who should care
Defenders responsible for AVideo deployments should assess exposure and implement compensating controls to prevent account takeover. AVideo operators, platform administrators, and security teams should review the vulnerability and implement remediation. Security teams should prioritize verifying exposure and implementing compensating controls to prevent account takeover. Defenders should also review compensating controls for exposed systems while is and
Why it matters
Defenders should care about CVE-2026-88870 because it allows attackers to replace victims' PGP 2FA public keys, potentially leading to account takeover or lockout. AVideo deployments should assess exposure and implement compensating controls.
- Potential account takeover if attacker knows victim's password
- Lockout of victims due to replaced PGP 2FA public key
- Need for verification of affected versions and remediation
Technical summary
The LoginControl plugin PGP key endpoints in WWBN AVideo lack CSRF token validation, allowing attackers to craft malicious pages with image tags pointing to savePublicKey.json.php to replace a logged-in victim's PGP 2FA public key. This can cause lockout or enable account takeover if the attacker knows the password. The vulnerability is a result of the lack of CSRF token validation in the PGP key endpoints, which allows attackers to perform malicious actions on behalf of the victim. Defenders should prioritize verifying exposure and implementing compensating controls to prevent account takeover.
Defensive priority
Defenders should prioritize verifying exposure and implementing compensating controls to prevent account takeover.
Recommended defensive actions
- Verify exposure by checking for vulnerable versions of AVideo
- Implement compensating controls to prevent account takeover
- Monitor for suspicious activity on PGP key endpoints
- Review vendor guidance for remediation
- Conduct a thorough review of affected systems
- Track exceptions and retest remediated assets
- Document evidence of remediation
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, but additional information on affected versions and remediation is needed. The vulnerability allows attackers to craft malicious pages with image tags pointing to savePublicKey.json.php to replace a logged-in victim's PGP 2FA public key. Defenders should verify exposure and implement compensating controls to prevent account takeover. The CVE Program record and NVD detail page provide source-provided CVE metadata and vulnerability assessment.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-88870 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-88870
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-88870 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-88870
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/WWBN/AVideo/security/advisories/GHSA-g4x9-vh2j-h7rj
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/wwbn-avideo-logincontrol-pgp-key-csrf-via-get-request
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.