CVE-2026-86719
Deferred Deferred - Pending Action

Cross-Site Request Forgery in AVideo CustomizeUser Plugin

Vulnerability report for CVE-2026-86719, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-10

Assigner: VulnCheck

Description

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 (master) contains a cross-site request forgery vulnerability in the CustomizeUser plugin endpoint plugin/CustomizeUser/swapUser.json.php. The endpoint takes users_id from $_REQUEST and invokes User::swapUser() without calling forbidIfNotPost() or forbidIfInvalidToken(), and the global autoCSRFGuard() check only runs for POST requests to *.json.php, so the action is reachable via GET. An attacker who causes an authenticated administrator's browser to issue a cross-origin GET (for example via an <img> tag or link) can replace that administrator's session with a non-admin user account, causing the administrator to lose administrative access until the swap is cancelled; swapping to another administrator account is rejected, so this is not privilege escalation. The JSON response also discloses the session_id. The CustomizeUser plugin is enabled by default, and no patch was available at the time of publication.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-10
Generated
2026-09-29
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wwbn avideo From c3edcc274c389816d434acadac07ee78eaf330c1 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-352 The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a cross-site request forgery (CSRF) flaw in WWBN AVideo. The CustomizeUser plugin endpoint plugin/CustomizeUser/swapUser.json.php allows an attacker to trick an authenticated administrator into making a GET request that swaps their session with a non-admin user account. The endpoint does not enforce POST-only requests or CSRF tokens, making it exploitable via malicious links or images.

Detection Guidance

To detect this vulnerability, monitor network traffic for GET requests to the vulnerable endpoint plugin/CustomizeUser/swapUser.json.php. Check for unusual session ID disclosures in JSON responses. Review server logs for GET requests to this path with user_id parameters.

Impact Analysis

An attacker could cause an administrator to lose access to their admin privileges by replacing their session with a non-admin account. The vulnerability also exposes the session ID in the JSON response. The impact is limited to session hijacking and loss of administrative control, not privilege escalation.

Mitigation Strategies

Disable the CustomizeUser plugin if not needed. Apply input validation to the users_id parameter. Ensure POST requests are enforced for sensitive actions. Update to a patched version if available. Monitor for unauthorized session swaps.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-86719. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart