Summary
CVE-2026-59256 is an authorization bypass vulnerability in WWBN AVideo caused by unbound, purpose-agnostic authorization tokens. The getToken() function generates tokens without binding them to a specific user identity or purpose, and the Gallery plugin’s sections.php renders a valid token to any unauthenticated visitor. This flaw carries a High severity rating (CVSS 8.7 / CVSS v4.0) and allows attackers to gain unauthorized access to restricted video content.
Technical details
- Root cause:
getToken()produces tokens containing only a salt string, timezone, and time window, with no binding to a user’s identity or to the specific resource/purpose the token is meant to protect. - Trigger condition:
plugin/Gallery/view/sections.phprenders a token (galleryToken) into the page for any visitor, without requiring authentication. - Attack vector: An unauthenticated, remote attacker sends a request to the Gallery section to obtain a valid token, then replays that token as
globalTokenagainst other endpoints such asview/hls.php. - Impact:
verifyToken()does not enforce resource-binding by default, so a token issued for one subsystem is accepted by another, letting an attacker bypass authorization and access restricted video playlists/content without credentials or user interaction.
Affected software
- WWBN AVideo — all versions/commits up to and including commit
9c39d8c8b4c1f75540788d6b391740852ceb0732 - No patched version has been published at time of writing
Severity
- CVSS v3.1: 7.5 (High) —
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N - CVSS v4.0: 8.7 (High) —
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N - Network attack vector, low attack complexity, no privileges or user interaction required
Mitigation and recommended actions
- Immediate: No official patched release is currently available; monitor the WWBN AVideo repository and GitHub Security Advisory GHSA-wq57-wxcr-rx6v for a fix and apply it as soon as it is released.
- Workarounds: Restrict rendering of tokens (e.g.,
galleryToken) to authenticated administrators only; bind tokens to specific user sessions/identities; enforce purpose-specific salts at every token generation call site; ensureverifyToken()performs resource-binding checks per video/subsystem before granting access. - Network mitigations: Restrict or authenticate access to the Gallery plugin endpoints (
plugin/Gallery/view/sections.php) at the network/WAF layer until a vendor fix is available, and monitor for anomalous reuse of tokens across unrelated video/session endpoints.

