PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-92578 WWBN CVE debrief

AVideo authentication bypass vulnerability allows attackers to authenticate as any user using the stored password hash, completely bypassing password verification. This vulnerability affects AVideo installations, particularly those responsible for authentication and password management systems. The vulnerability has a high impact on system security, allowing unauthorized access to sensitive information. Defenders should assess exposure and prioritize remediation to prevent exploitation.

Vendor
WWBN
Product
AVideo
CVSS
CRITICAL 9.2
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-16
Original CVE updated
2026-09-22
Advisory published
2026-09-16
Advisory updated
2026-09-22

Who should care

Defenders responsible for authentication and password management systems, as well as those managing AVideo installations, should assess exposure and prioritize remediation. This includes system administrators, security teams, and IT personnel responsible for maintaining AVideo installations. Additionally, defenders responsible for monitoring system logs and implementing security measures should also be aware of this vulnerability and take necessary actions

Why it matters

The AVideo authentication bypass vulnerability allows attackers to authenticate as any user using the stored password hash, completely bypassing password verification. Defenders responsible for authentication and password management systems, as well as those managing AVideo installations, should assess exposure and prioritize remediation.

  • Attackers can authenticate as any user without knowing the actual password
  • Compromised password hashes can be used for unauthorized access
  • Additional security measures are required to prevent exploitation
  • Remediation priority is high for authentication and password management systems

Technical summary

The AVideo authentication bypass vulnerability occurs in two independent code paths, loginFromRequest() and encryptPasswordVerify(). Attackers who obtain the stored users.password hash value can authenticate as any user by submitting the hash directly to login endpoints, completely bypassing password verification. This vulnerability has a significant impact on system security, allowing unauthorized access to sensitive information. Defenders should assess exposure and prioritize remediation to prevent exploitation. The vulnerability affects AVideo installations, particularly those responsible for authentication and password management systems.

Defensive priority

High priority for authentication and password management systems

Recommended defensive actions

  • Review and update authentication and password management systems to prevent exploitation
  • Implement additional security measures to protect against unauthorized access
  • Monitor system logs for suspicious activity
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The CVE record and NVD entry provide details on the authentication bypass vulnerability in AVideo. The vulnerability allows attackers to authenticate as any user using the stored password hash. Evidence is limited to the CVE record and NVD entry, and defenders should verify the vulnerability's existence and scope. The stored password hash can be used for unauthorized access, and additional security measures are required to prevent exploitation.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-92578 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-92578

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-92578 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-92578

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.