Unauthenticated Stream Credential Exposure in AVideo by WWBN
CVE-2026-82645

9.2CRITICAL

Key Information:

Vendor

Wwbn

Status
Vendor
CVE Published:
30 August 2026

What is CVE-2026-82645?

The AVideo platform, specifically versions before commit e01e41ecc, contains a significant security flaw where stream credentials are exposed through an insecure endpoint. An attacker can manipulate the 'token' parameter in the getLiveKey.json.php file, bypassing critical access controls that typically safeguard stream ownership and access checks. This vulnerability allows unauthorized users to retrieve sensitive stream keys and URLs for external platforms, including YouTube, Facebook, and Twitch, without any authentication. The flaw stems from the use of a non-user-bound encryption method, which enables attackers to forge tokens easily and exploit the system for unauthorized access to stream data.

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

rajivraj
.