IDOR Vulnerability in WWBN AVideo Open Source Video Platform
CVE-2026-40907
6.5MEDIUM
What is CVE-2026-40907?
AVideo, an open-source video platform developed by WWBN, presents a security flaw in its earlier versions (29.0 and prior). The vulnerability exists within the endpoint plugin/Live/view/Live_restreams/list.json.php, allowing authenticated users with streaming permissions to access other users' live restream configurations. This includes sensitive information such as third-party platform stream keys and OAuth tokens (including access_token and refresh_token) for major services like YouTube Live, Facebook Live, and Twitch. The issue has been addressed in commit d5992fff2811df4adad1d9fc7d0a5837b882aed7.
Affected Version(s)
AVideo <= 29.0
