Skip to content
CVE Alert: CVE-2026-86720 – WWBN

CVE Alert: CVE-2026-86720 – WWBN

Redpacketsecurity admin September 9, 2026

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate ownership of live_restreams_id in resendRestreamer.json.php, allowing authenticated users with canStream to access other users’ restream destinations. Attackers can broadcast their live stream to victim-configured restream destinations by supplying arbitrary live_restreams_id values, hijacking YouTube, , or Twitch streams using victim stream keys.

## AI Summary Analysis

**Risk verdict:** High risk with urgent remediation: a proof of concept exists, and a minimally privileged streaming account may abuse trusted broadcast configuration.

**Why this matters:** Successful exploitation can expose third-party streaming credentials and redirect broadcasts to attacker-controlled content, causing reputational damage, loss of audience trust and possible unauthorised disclosure. Organisations using live streaming for events, training, media or customer communications face operational disruption even though platform availability is not directly affected. The available SSVC assessment indicates proof-of-concept activity, but not confirmed weaponised exploitation.

**Most likely attack path:** An attacker first obtains or creates a legitimate account with streaming permission, then makes a network request to the affected function while substituting an identifier belonging to another user. Low attack complexity and no victim interaction make this practical once an account is available. Scope remains confined to the application, but compromised external stream destinations can extend business impact beyond the host.

**Who is most exposed:** Internet-facing AVideo installations that permit self-service registration, broad streaming privileges or multiple tenant-managed restream targets are most exposed. Shared hosting and community media deployments may have weaker account governance and limited monitoring.

Alert on requests to the restreaming function using identifiers outside the caller’s ownership.

Correlate one account with changes or sends to multiple unrelated destinations.

Review streaming-platform audit logs for unexpected key use, titles or broadcast origins.

Hunt for newly created streaming accounts followed by immediate restream activity.

Mitigation and prioritisation:

Apply the vendor’s corrective update beyond the affected code revision; verify ownership checks in testing.

Restrict streaming privileges and disable self-service access where unnecessary.

Rotate potentially exposed stream keys and review destination ownership.

Add authorisation checks at the application or reverse-proxy layer as a temporary control.

Test live workflows during change management, then audit historical restream activity.

A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.

If you like the site, please support us on Patreon or Buy Me A Coffee using the buttons below.