CVE-2026-88725

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-88725 describes a missing authorization vulnerability found in AVideo, specifically affecting versions up to c3edcc274c389816d434acadac07ee78eaf330c1. This flaw resides within the `add.json.php` endpoint of the SocialMediaPublisher plugin. The vulnerability allows authenticated users to manipulate other users' OAuth token records. An attacker can provide arbitrary row IDs to overwrite an existing user's stored `access_token` and `refresh_token`. Following this, the compromised record can be deleted, which severs the victim's provider linkage.

Description
-

Social media

Hype score
Not currently trending

References

Sources include official advisories and independent security research.