Insecure Direct Object Reference in Streama by StreamaServer
CVE-2026-73039

5.3MEDIUM

Key Information:

Vendor

Fosowl

Vendor
CVE Published:
13 August 2026

What is CVE-2026-73039?

An insecure direct object reference vulnerability exists in Streama's ViewingStatusController, permitting authenticated users to access and modify other users' viewing status records without proper authorization. This flaw may allow attackers to enumerate users' watch progress, delete viewing history arbitrarily, and alter the Continue Watching dashboard for other users by manipulating primary keys. The issue raises significant concerns regarding unauthorized data access and user privacy, necessitating immediate attention and remediation.

Affected Version(s)

AgenticSeek 0 <= 2.41.1

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.