{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/logincontrol/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:avideo:logincontrol:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-92914"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["LoginControl"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["AVideo"],"content_html":"\u003cp\u003eAVideo LoginControl contains an authentication bypass vulnerability within its PGP second-factor verification process. The vulnerability stems from an insecure implementation of challenge response verification that uses loose equality comparison (==) against an uninitialized session variable. Because the code evaluates an uninitialized session variable as null, an attacker possessing a victim's account password can trigger this bypass by submitting a parameter-less GET request to the 'verifyChallenge.json.php' endpoint. This results in a condition where the check evaluates null == null, allowing the system to erroneously mark the second-factor authentication as complete. This flaw grants unauthorized access to accounts that have PGP-based multi-factor authentication enabled, effectively negating the security controls intended to protect these identities. Defenders should identify instances of AVideo LoginControl and monitor web server access logs for anomalous requests to the identified verification endpoint.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-92914 allows unauthenticated actors who have obtained valid user credentials to bypass second-factor authentication controls. This leads to unauthorized account access, potential data exfiltration, and persistence within the application environment. The severity is assessed as high due to the bypass of critical authentication controls in enterprise media management workflows.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDeploy the provided Sigma rule to detect suspicious access to the vulnerable verification endpoint.\u003c/li\u003e\n\u003cli\u003eReview web server logs for requests to 'verifyChallenge.json.php' that lack expected parameters or authentication headers.\u003c/li\u003e\n\u003cli\u003eIdentify all instances of AVideo LoginControl within the environment and coordinate with the vendor or upstream project for available security patches.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-17T13:56:59Z","date_published":"2026-09-17T13:56:59Z","id":"https://feed.craftedsignal.io/briefs/2026-09-avideo-auth-bypass/","summary":"An authentication bypass vulnerability in AVideo LoginControl allows attackers with a victim's password to circumvent PGP two-factor authentication by exploiting loose equality checks.","title":"Authentication Bypass in AVideo LoginControl via PGP Verification","url":"https://feed.craftedsignal.io/briefs/2026-09-avideo-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - LoginControl","version":"https://jsonfeed.org/version/1.1"}