Information Disclosure in AVideo Product by WWBN
CVE-2026-86727
8.7HIGH
What is CVE-2026-86727?
AVideo, up to version 29.0, contains a security flaw in the stats.json.php endpoint that permits unauthenticated access to sensitive data, including stream keys and m3u8 URLs. Attackers can exploit this vulnerability to enumerate private, unlisted, and group-restricted live streams by analyzing the hidden_applications array returned in the JSON response. This poses a significant risk to the confidentiality of streaming credentials, potentially leading to unauthorized access to live stream content.
Affected Version(s)
AVideo 0 <= 29.0
