CVE-2026-81732 MEDIUM

CVE-2026-81732: WWBN AVideo through 30.0 Information Disclosure via report4.json.php

Vendor Wwbn
Product AVideo
Weakness CWE-200 · Info exposure
Published August 28, 2026
Last update August 29, 2026

CVSS base score

6.9/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

What the vulnerability does

01Description

WWBN AVideo through version 30.0 fails to enforce authentication on the report4.json.php and report4.1.json.php endpoints, allowing unauthenticated access to user registration statistics. Attackers can send GET requests to these endpoints to retrieve daily and cumulative user-registration counts without any session or authorization.

Key dates

02Disclosure timeline

August 28, 2026 CVE published
August 29, 2026 Record updated

Related vulnerabilities

04Related CVE