Access Control Flaw in WWBN AVideo Affects Playlist Scheduling
CVE-2026-34245
6.3MEDIUM
What is CVE-2026-34245?
The WWBN AVideo platform, an open-source video hosting solution, contains an access control issue that impacts versions up to and including 26.0. An authenticated user with streaming permission can exploit the plugin/PlayLists/View/Playlists_schedules/add.json.php endpoint to create or modify broadcast schedules for any playlist, irrespective of ownership. This breach allows the attacker’s schedules to execute under the playlist owner's identity, resulting in potential content hijacking and disruption of live streams. A patch has been issued to mitigate this vulnerability, as detailed in commit 1e6dc20172de986f60641eb4fdb4090f079ffdce.
Affected Version(s)
AVideo <= 26.0
