Authorization Flaw in AVideo Allows User Link Modification
CVE-2026-89252
7.1HIGH
What is CVE-2026-89252?
AVideo's addLiveLink.php file is prone to an authorization oversight that permits authenticated users to modify another user's LiveLink metadata and HLS source. By exploiting this vulnerability, a user with 'canStream' permissions can supply an existing linkId, resulting in a redirection of viewers to media controlled by the attacker. This flaw highlights the importance of proper ownership verification mechanisms to safeguard user-generated content.
Affected Version(s)
AVideo 0
