Unauthenticated Stream Credential Exposure in AVideo by WWBN
CVE-2026-82645
9.2CRITICAL
What is CVE-2026-82645?
The AVideo platform, specifically versions before commit e01e41ecc, contains a significant security flaw where stream credentials are exposed through an insecure endpoint. An attacker can manipulate the 'token' parameter in the getLiveKey.json.php file, bypassing critical access controls that typically safeguard stream ownership and access checks. This vulnerability allows unauthorized users to retrieve sensitive stream keys and URLs for external platforms, including YouTube, Facebook, and Twitch, without any authentication. The flaw stems from the use of a non-user-bound encryption method, which enables attackers to forge tokens easily and exploit the system for unauthorized access to stream data.
