Critical CSRF Vulnerability in WWBN AVideo Exposes Admins to Attacks

Critical CSRF Vulnerability in WWBN AVideo Exposes Admins to Attacks

First seen 9 Sep 2026, 00:42 UTC Redpacketsecuritygithub.com 69.0

Article Content

Browse articles
ThreatCluster

A cross-site request forgery (CSRF) vulnerability has been identified in WWBN AVideo, specifically in the deleteHistory.json.php and finishAll.json.php files. This flaw allows unauthenticated attackers to manipulate live history by sending GET requests without CSRF token validation. The vulnerability affects internet-facing deployments with web administration, particularly streaming platforms with broad administrator privileges. Attackers can craft malicious pages that, when visited by an administrator, can delete live transmission history or mark streams as finished. The CVE-2026-86718 was published on September 8, 2026, and there is proof-of-concept exploitation available. Urgent remediation is required as the risk of operational disruption is high, although there are no confirmed active exploitations reported yet. Administrators are advised to monitor logs and restrict access until a patch is applied.

Key Points: • CVE-2026-86718 exposes WWBN AVideo to CSRF attacks. • Attackers can delete live history or mark streams finished via crafted GET requests. • Urgent patching is required for affected deployments, especially those with broad admin access.

Ask AI about this cluster

Timeline

2026-09-08
CVE-2026-86718 published
A CSRF vulnerability in WWBN AVideo was officially disclosed, affecting admin functionalities.
Redpacketsecurity
2026-09-09
Vulnerability details released
GitHub advisory outlines the exploit method and affected files, confirming the lack of CSRF protection.
github.com