CVE-2026-90537 | WWBN AVideo Scheduler Email sendEmail.json.php sendEmail daily token improper authorization

SecurityVulns

A vulnerability, which was classified as critical, was found in WWBN AVideo. This issue affects the function sendEmail of the file plugin/Scheduler/sendEmail.json.php of the component Scheduler Email. Executing a manipulation of the argument daily token can lead to improper authorization.

This vulnerability is tracked as CVE-2026-90537. The attack can be launched remotely. No exploit exists.

It is advisable to implement a patch to correct this issue.VulDB Recent EntriesRead More