Information Disclosure in AVideo Product by WWBN
CVE-2026-86727

8.7HIGH

Key Information:

Vendor

Wwbn

Status
Vendor
CVE Published:
8 September 2026

What is CVE-2026-86727?

AVideo, up to version 29.0, contains a security flaw in the stats.json.php endpoint that permits unauthenticated access to sensitive data, including stream keys and m3u8 URLs. Attackers can exploit this vulnerability to enumerate private, unlisted, and group-restricted live streams by analyzing the hidden_applications array returned in the JSON response. This poses a significant risk to the confidentiality of streaming credentials, potentially leading to unauthorized access to live stream content.

Affected Version(s)

AVideo 0 <= 29.0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

manus-use
.