Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-84480

CRITICAL NVD
CVSS Score 9.8
Severity CRITICAL
Published Sep 01, 2026
Vendor unknown

Description

WWBN AVideo fails to validate password recovery token expiration in userRecoverPassSave.json.php, allowing attackers to use expired tokens to reset account passwords indefinitely. Attackers who obtain a recovery token can use it at any time to change the target account's password and gain full account access.

References