Skip to content
CVE Alert: CVE-2026-86718 – WWBN

CVE Alert: CVE-2026-86718 – WWBN

Redpacketsecurity admin September 9, 2026

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vulnerability in deleteHistory.json.php and finishAll.json.php that allows unauthenticated attackers to mutate live history by making GET requests without CSRF token validation. Attackers can craft malicious pages that trigger administrator browsers to delete all live transmission history or mark streams as finished when an admin visits the attacker-controlled site.

## AI Summary Analysis

**Risk verdict:** High operational risk requiring urgent remediation because SSVC records proof-of-concept exploitation, although the supplied data does not indicate confirmed active exploitation or KEV listing.

**Why this matters:** A successful attack could alter or erase operational records, undermining auditability, incident reconstruction and service-management decisions. The realistic attacker goal is to induce a privileged administrator’s browser to perform unintended state-changing actions, rather than to obtain confidential data or directly compromise the server.

**Most likely attack path:** The attacker needs only network reachability and a victim administrator to visit a crafted page; no account, special access or complex preparation is required. Passive browser interaction can cause cross-site requests, with integrity impact concentrated on the application’s operational state; scope is unchanged, so lateral movement is not inherent but could follow if administrators reuse privileged sessions elsewhere.

**Who is most exposed:** Internet-facing deployments with web administration available to staff, particularly streaming platforms operated by small teams with broad administrator privileges. Environments where administrators browse external content from the same session are especially at risk.

Alert on unexpected GET requests to the affected history-management endpoints.

Review audit logs for bulk deletion or stream-finalisation actions without corresponding operator activity.

Correlate administrator sessions with unusual referrers, origins or rapid state changes.

Check browser and proxy telemetry for suspicious external pages visited during privileged sessions.

Mitigation and prioritisation:

Apply the vendor’s corrective release urgently; treat internet-facing administrative instances as the highest patching tier.

Until patched, restrict administrative access by VPN, allow-listing or a management network.

Enforce re-authentication for destructive actions and monitor administrator sessions.

Test the fix in staging, then expedite change approval; preserve relevant logs before making changes.

A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.

If you like the site, please support us on Patreon or Buy Me A Coffee using the buttons below.

Extracted Entities