Critical CSRF Vulnerability in WWBN AVideo Exposes Admins to Attacks
Article Content
A cross-site request forgery (CSRF) vulnerability has been identified in WWBN AVideo, specifically in the deleteHistory.json.php and finishAll.json.php files. This flaw allows unauthenticated attackers to manipulate live history by sending GET requests without CSRF token validation. The vulnerability affects internet-facing deployments with web administration, particularly streaming platforms with broad administrator privileges. Attackers can craft malicious pages that, when visited by an administrator, can delete live transmission history or mark streams as finished. The CVE-2026-86718 was published on September 8, 2026, and there is proof-of-concept exploitation available. Urgent remediation is required as the risk of operational disruption is high, although there are no confirmed active exploitations reported yet. Administrators are advised to monitor logs and restrict access until a patch is applied.
Key Points: • CVE-2026-86718 exposes WWBN AVideo to CSRF attacks. • Attackers can delete live history or mark streams finished via crafted GET requests. • Urgent patching is required for affected deployments, especially those with broad admin access.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.