Authentication Bypass in WWBN AVideo Streaming Platform
CVE-2026-33716

9.4CRITICAL

Key Information:

Vendor

Wwbn

Status
Vendor
CVE Published:
23 March 2026

What is CVE-2026-33716?

The WWBN AVideo platform, an open-source solution for video streaming, is vulnerable due to a flaw in the live stream control endpoint. In versions up to and including 26.0, the control.json.php file improperly handles user-supplied parameters, specifically the streamerURL. This allows attackers to manipulate token verification requests, redirecting them to malicious servers that always yield a success response. Consequently, this vulnerability facilitates unauthorized control over active live streams, enabling malicious users to terminate sessions, initiate or halt recordings, and probe for active streams, undermining the platform's security integrity. A patch for this vulnerability has been made available in commit 388fcd57.

Affected Version(s)

AVideo <= 26.0

References

CVSS V3.1

Score:
9.4
Severity:
CRITICAL
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.