CVE-2026-86723
Gravedad CVSS v4.0:
ALTA
Tipo:
CWE-287
Autenticación incorrecta
Fecha de publicación:
08/09/2026
Última modificación:
08/09/2026
Descripción
*** Pendiente de traducción *** AVideo through c3edcc274c389816d434acadac07ee78eaf330c1 contains an authentication bypass vulnerability in LoginControl::verifyChallenge() that uses loose comparison (==) instead of strict comparison (===) against unset session values. Attackers with only a password can submit an empty request to verifyChallenge.json.php to bypass PGP two-factor authentication and gain full authenticated access.
Impacto
Puntuación base 4.0
8.60
Gravedad 4.0
ALTA
Puntuación base 3.x
8.10
Gravedad 3.x
ALTA


