Authentication Bypass in WWBN AVideo Streaming Platform
CVE-2026-33716
What is CVE-2026-33716?
The WWBN AVideo platform, an open-source solution for video streaming, is vulnerable due to a flaw in the live stream control endpoint. In versions up to and including 26.0, the control.json.php file improperly handles user-supplied parameters, specifically the streamerURL. This allows attackers to manipulate token verification requests, redirecting them to malicious servers that always yield a success response. Consequently, this vulnerability facilitates unauthorized control over active live streams, enabling malicious users to terminate sessions, initiate or halt recordings, and probe for active streams, undermining the platform's security integrity. A patch for this vulnerability has been made available in commit 388fcd57.
Affected Version(s)
AVideo <= 26.0
