Missing Authentication Vulnerability in AVideo by WWBN
CVE-2026-84187
8.8HIGH
What is CVE-2026-84187?
AVideo has a vulnerability that enables unauthenticated attackers to manipulate scheduled broadcasts. By exploiting a flaw in the on_publish.php endpoint, attackers can send crafted POST requests that alter the status of scheduled broadcasts without requiring authentication. This is achieved through an unprotected RTMP callback mechanism which allows unauthorized modifications by simply supplying specially constructed stream keys. Such vulnerabilities put live broadcasts at risk of unauthorized cancellations and could lead to significant disruptions in scheduled streaming content.
Affected Version(s)
AVideo 0 <= 29.0
