MEDIUMVulnerability

CVE-2026-90542

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate that logged-in users can access live schedules before creating reminders via remindMe.json.php. Authenticated attackers can create scheduler reminders for private live schedules they cannot view and learn the private schedule title from the generated email job.

Properties

severity
MEDIUM
score
5.4
cve_id
CVE-2026-90542
signal_observed_at
2026-09-21T23:07:07+00:00
vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
published_at
2026-09-12T13:16:52.353
last_modified
2026-09-15T18:19:36.713

Related Entities (2)

HAS_WEAKNESS (1)

[Weakness]Authorization Bypass Through User-Controlled Key

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-90542 — Ninja Signal Threat Intelligence | Ninja Signal