CRITICAL 9.3 NVD
CVE-2026-84480
WWBN AVideo fails to validate password recovery token expiration in userRecoverPassSave.json.php, allowing attackers to use expired tokens to reset account pass
WWBN AVideo fails to validate password recovery token expiration in userRecoverPassSave.json.php, allowing attackers to use expired tokens to reset account passwords indefinitely. Attackers who obtain a recovery token can use it at any time to change the target account's password and gain full account access.
References
- https://github.com/WWBN/AVideo/security/advisories/GHSA-j9p7-hm85-9v77
- https://www.vulncheck.com/advisories/wwbn-avideo-password-recovery-token-expiration-bypass
This critical severity vulnerability with a CVSS score of 9.3 was published on 2026-09-01 via NVD.
Risk Timeline
CVE Disclosed2026-09-01 · 0 days ago
Remediation Resources
vulnfeed aggregates 11552 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.