Authorization Bypass in AVideo by WWBN
CVE-2026-86721

8.7HIGH

Key Information:

Vendor

Wwbn

Status
Vendor
CVE Published:
8 September 2026

What is CVE-2026-86721?

AVideo has been identified with an authorization bypass vulnerability that allows attackers to exploit a session cookie, 'key', which can override the $_REQUEST['key'] parameter in the saveLive.php script and associated endpoints. This flaw enables malicious actors to publish content to any user's RTMP stream without requiring authentication, jeopardizing the security of live broadcasts. The risk is heightened by the ability to hijack streams using a static stream key, potentially leading to unauthorized access and content manipulation.

Affected Version(s)

AVideo 0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

santhreal
.