Missing Authentication Vulnerability in AVideo by WWBN
CVE-2026-84187

8.8HIGH

Key Information:

Vendor

Wwbn

Status
Vendor
CVE Published:
1 September 2026

What is CVE-2026-84187?

AVideo has a vulnerability that enables unauthenticated attackers to manipulate scheduled broadcasts. By exploiting a flaw in the on_publish.php endpoint, attackers can send crafted POST requests that alter the status of scheduled broadcasts without requiring authentication. This is achieved through an unprotected RTMP callback mechanism which allows unauthorized modifications by simply supplying specially constructed stream keys. Such vulnerabilities put live broadcasts at risk of unauthorized cancellations and could lead to significant disruptions in scheduled streaming content.

Affected Version(s)

AVideo 0 <= 29.0

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
None
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

rajivraj
.