#VU125480 Missing Authorization in AVideo - CVE-2026-33759
Published: April 8, 2026
AVideo
World Wide Broadcast Network
Description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to missing authorization in objects/playlistsVideos.json.php when handling requests with a playlists_id parameter. A remote attacker can send a specially crafted request with a sequential playlist identifier to disclose sensitive information.
Private playlists, including watch_later and favorite playlists, can be enumerated because playlist identifiers are sequential integers.