
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-30885 is an unauthenticated Insecure Direct Object Reference (IDOR) vulnerability in WWBN AVideo, an open-source video platform, that allows any unauthenticated visitor to retrieve playlist names, video IDs, and playlist status for any user on the platform. The vulnerability affects all AVideo versions prior to 25.0 and was disclosed on March 6, 2026, by researchers Akokonunes and neo-ai-engineer via a GitHub Security Advisory (Github Advisory). It carries a CVSS v3.1 base score of 5.3 (Medium) and a CVSS v4.0 base score of 5.5 (Medium) (Github Advisory).
The root cause is the complete absence of authentication and authorization checks in the /objects/playlistsFromUser.json.php endpoint (CWE-306: Missing Authentication for Critical Function; CWE-862: Missing Authorization; CWE-639: Authorization Bypass Through User-Controlled Key). The endpoint accepts a users_id GET parameter and directly passes it to PlayList::getAllFromUser() without calling User::isLogged() or verifying that the requesting user matches the target users_id, making it a classic IDOR (Github Advisory). The same pattern was also present in the related objects/playlistsFromUserVideos.json.php endpoint, which was patched simultaneously (AVideo Commit). No special tools or privileges are required — a simple unauthenticated HTTP GET request is sufficient to exploit the flaw.
Successful exploitation results in a confidentiality breach: any unauthenticated attacker can enumerate valid user IDs by iterating through the users_id parameter and retrieve all playlist names, video IDs, and playlist statuses for every user on the platform (Github Advisory). There is no integrity or availability impact. The exposed data can reveal private content preferences and user interests, enabling targeted social engineering attacks or serving as reconnaissance for further exploitation of the platform or its users.
A public proof-of-concept exploit is available in the form of a simple curl command documented in the GitHub Security Advisory: curl "https://TARGET/objects/playlistsFromUser.json.php?users_id=1" (AVideo Advisory). The EPSS score is approximately 0.076–0.118%, indicating a low but non-negligible probability of exploitation in the wild within 30 days. There is no evidence of active in-the-wild exploitation or threat actor attribution at this time, and the CVE is not listed in the CISA KEV catalog (Github Advisory).
curl "https://TARGET/objects/playlistsFromUser.json.php?users_id=1"users_id (e.g., 1, 2, 3, ...) to identify valid user accounts — a non-empty JSON response indicates a valid user ID.users_id, collect playlist names, video IDs, and playlist statuses to build a profile of user interests and private content preferences./objects/playlistsFromUser.json.php with sequentially incrementing users_id values from a single or small set of IP addresses./objects/playlistsFromUserVideos.json.php with varying users_id parameters.playlistsFromUser.json.php?users_id=<integer> without any associated session cookie or authentication header, particularly from automated user-agent strings.The vulnerability is fixed in AVideo version 25.0. The patch adds a visibility check so that only the playlist owner or an administrator can retrieve non-public playlists; unauthenticated or unauthorized requests are restricted to public playlists only (AVideo Commit). Administrators unable to upgrade immediately should consider blocking unauthenticated access to the /objects/playlistsFromUser.json.php and /objects/playlistsFromUserVideos.json.php endpoints via web server configuration (e.g., requiring authentication at the reverse proxy level). Upgrading to version 25.0 or later is the recommended long-term remediation (Github Advisory).
The vulnerability was reported by researchers Akokonunes and neo-ai-engineer and published as a GitHub Security Advisory on March 6, 2026, with the fix committed by the AVideo maintainer (DanielnetoDotCom) shortly after (AVideo Advisory). The issue received coverage from several vulnerability tracking and threat intelligence platforms including CVEFeed, VulDB, and Radar by Offseq, reflecting standard community awareness for a medium-severity open-source disclosure. No significant vendor statements beyond the advisory or notable researcher commentary beyond the original report have been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."