CVE-2026-86722
Deferred Deferred - Pending Action

Authentication Bypass in AVideo via Stale SQL Cache

Vulnerability report for CVE-2026-86722, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-10

Assigner: VulnCheck

Description

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains an authentication bypass vulnerability where sqlDAL caches empty result sets that writeSql never invalidates. Attackers with a valid password can bypass email two-factor authentication on new devices because the confirmation code hash fails to generate from the stale cached empty result.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-10
Generated
2026-09-29
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
avideo avideo *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-287 When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

AVideo has an authentication bypass flaw due to sqlDAL caching empty result sets that are never cleared by writeSql. This allows attackers with a valid password to skip email-based two-factor authentication on new devices because the confirmation code hash is generated from stale cached data instead of fresh input.

Impact Analysis

If you use AVideo, an attacker could gain unauthorized access to your account even with your password by bypassing two-factor authentication. This could lead to data theft, account manipulation, or further compromise of connected systems.

Compliance Impact

This vulnerability could violate compliance requirements that mandate strong authentication (e.g., GDPR's security principle or HIPAA's access controls) by allowing unauthorized access despite multi-factor authentication. Organizations may face penalties for failing to protect user data adequately.

Mitigation Strategies

Update AVideo to the latest commit or version to ensure the sqlDAL caching issue is resolved and stale empty result sets are properly invalidated.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-86722. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart