CVE-2026-92577

CVE-2026-92577 published: In AVideo through 29.0, the API get_api_video endpoint contains a broken access control vulnerability in the clean_title branch that returns user-group-restricted videos with owner PII to anonymous callers. Attackers can query videos by their public slug to...

View full NVD advisory → ← Back to CVE watch