Access Control Flaw in WWBN AVideo Affects Playlist Scheduling
CVE-2026-34245

6.3MEDIUM

Key Information:

Vendor

Wwbn

Status
Vendor
CVE Published:
27 March 2026

What is CVE-2026-34245?

The WWBN AVideo platform, an open-source video hosting solution, contains an access control issue that impacts versions up to and including 26.0. An authenticated user with streaming permission can exploit the plugin/PlayLists/View/Playlists_schedules/add.json.php endpoint to create or modify broadcast schedules for any playlist, irrespective of ownership. This breach allows the attacker’s schedules to execute under the playlist owner's identity, resulting in potential content hijacking and disruption of live streams. A patch has been issued to mitigate this vulnerability, as detailed in commit 1e6dc20172de986f60641eb4fdb4090f079ffdce.

Affected Version(s)

AVideo <= 26.0

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.