Skip to content
CVE Alert: CVE-2026-86727 – WWBN

CVE Alert: CVE-2026-86727 – WWBN

Redpacketsecurity admin September 9, 2026

AVideo through 29.0 contains an information disclosure vulnerability in plugin/Live/stats.json.php that allows unauthenticated attackers to retrieve stream keys and m3u8 URLs by accessing the endpoint without authentication. Attackers can enumerate private, unlisted, and group-restricted live streams by parsing the hidden_applications array in the JSON response to obtain sensitive streaming credentials.

This is a high-risk exposure for internet-facing deployments, requiring rapid remediation; KEV, SSVC exploitation status and EPSS are not provided, so priority-one status cannot be confirmed.

An unauthenticated party may obtain operationally sensitive streaming data without compromising an account or changing system content. Exposed credentials and stream locations could enable unauthorised viewing, redistribution, privacy breaches, reputational damage, and disruption of paid or restricted broadcasts.

### Most likely attack path

An attacker sends a direct network request to the affected PHP endpoint, with low complexity, no privileges and no user interaction required. The response can then be automated to enumerate restricted broadcasts and extract usable stream access details; scope is unchanged, so direct lateral movement is not implied, although compromised streaming credentials may provide access to connected media workflows.

### Who is most exposed

Internet-facing AVideo instances hosting private, unlisted, group-restricted or commercially sensitive live content are the primary concern. Shared hosting, self-managed community platforms and installations placed directly behind permissive reverse proxies may have broader exposure than centrally managed services.

Review web-server logs for unauthenticated requests to `stats.json.php`, especially repeated or scripted access.

Alert on unusual enumeration of live-stream metadata or rapid requests from one source.

for stream-key use from unfamiliar IP addresses, geographies or user agents.

Check proxy, WAF and application logs for responses containing hidden stream metadata.

Validate whether exposed keys or URLs were subsequently accessed by unknown clients.

### Mitigation and prioritisation

Apply the vendor’s security fix promptly; prioritise internet-facing systems and sensitive broadcasts.

Restrict the endpoint at the reverse proxy or WAF pending patch deployment, while testing live-stream functionality.

Rotate potentially exposed stream keys and invalidate affected URLs after containment.

Enforce authentication and network allow-listing where operationally feasible.

Obtain KEV, SSVC and EPSS results before final queueing; absence of those signals is an uncertainty, not evidence of low exploitation risk.

A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.

If you like the site, please support us on Patreon or Buy Me A Coffee using the buttons below.

Extracted Entities

Attack Types (1)

Platforms (1)