Critical CVEs Identified in WWBN AVideo Streaming Platform

Critical CVEs Identified in WWBN AVideo Streaming Platform

First seen 9 Sep 2026, 00:42 UTC Redpacketsecuritygithub.comwww.vulncheck.com 69.0

Article Content

Browse articles
ThreatCluster

Two critical vulnerabilities, CVE-2026-86720 and CVE-2026-86721, were disclosed for the WWBN AVideo platform on September 8, 2026. CVE-2026-86720 allows authenticated users to hijack live streams by manipulating identifiers, while CVE-2026-86721 enables attackers to publish to any user's RTMP stream without authentication using a session cookie override. Both vulnerabilities pose high risks to organizations using AVideo for live streaming, potentially leading to reputational damage and operational disruptions. Internet-facing installations, especially those allowing self-service registration or broad streaming privileges, are particularly vulnerable. Remediation is urgent, with recommendations to apply vendor patches and restrict streaming privileges. No confirmed exploitation has been reported yet, but proof-of-concept code exists for CVE-2026-86720. Organizations are advised to monitor their streaming activity closely and review audit logs for unusual behavior.

Key Points: • CVE-2026-86720 allows stream hijacking via identifier manipulation. • CVE-2026-86721 enables unauthorized publishing to any RTMP stream. • Both vulnerabilities require urgent remediation to prevent reputational damage.

Ask AI about this cluster

Timeline

2026-09-08
CVE-2026-86720 published
CVE-2026-86720 disclosed, allowing authenticated users to hijack streams by manipulating identifiers.
Redpacketsecurity
2026-09-08
CVE-2026-86721 published
CVE-2026-86721 disclosed, enabling attackers to publish to any RTMP stream without authentication.
Redpacketsecurity
2026-09-09
Current status update
Both vulnerabilities are classified as high risk, requiring urgent remediation by affected organizations.
Redpacketsecurity