Skip to content
CVE Alert: CVE-2026-86721 – WWBN

CVE Alert: CVE-2026-86721 – WWBN

Redpacketsecurity admin September 9, 2026

AVideo through commit c3edcc274c contains an authorization bypass vulnerability where a session cookie named ‘key’ with value ‘value’ overrides the $_REQUEST[‘key’] parameter in saveLive.php and related endpoints. Attackers can publish to any user’s RTMP stream without authentication by using the known constant stream key value to hijack live broadcasts.

High-risk internet-facing issue requiring rapid remediation, although no KEV, SSVC exploitation state, PoC, or EPSS indicators were provided to confirm active exploitation or assign Priority 1 status.

An unauthenticated attacker could alter live broadcast content, impersonate legitimate publishers, and damage trust in the service without needing to compromise an account. The primary business impact is loss of content integrity, including hijacked events, reputational harm, and possible regulatory or contractual consequences for hosted broadcasts. Confidentiality and service availability appear less directly affected.

### Most likely attack path

The attack is remotely reachable (AV:N), requires low effort (AC:L), no privileges (PR:N), and no user interaction (UI:N), making automated internet-wide probing plausible. Scope is unchanged, so the direct impact remains within the affected application; however, compromised publishing capability could be leveraged for social engineering or to distribute malicious content to viewers.

### Who is most exposed

Exposed self-hosted installations serving live video, particularly publicly reachable community, education, media, or event-streaming platforms, are the main concern. Deployments with administrative endpoints directly internet-facing or weak reverse-proxy controls warrant priority review.

Alert on unauthorised requests to live-stream publishing endpoints.

Compare publisher identity, stream ownership, and source IP against expected account activity.

Review web logs for repeated requests containing unusual or fixed authentication parameters.

Monitor sudden stream changes, unexpected publishing times, and abnormal broadcaster geography.

### Mitigation and prioritisation

Apply the vendor’s security fix or a release containing it urgently; validate the deployed commit, not just the reported application version.

Treat as priority 1 if later confirmed KEV-listed or EPSS is at least 0.5.

Restrict publishing endpoints through authentication-aware reverse-proxy rules and network allow-lists where feasible.

Rotate affected stream credentials and review recent broadcasts for tampering.

Test in staging first, then expedite change approval with rollback and post-upgrade verification.

A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.

If you like the site, please support us on Patreon or Buy Me A Coffee using the buttons below.

Extracted Entities

Companies (1)

Platforms (1)