CVE-2026-86727
AVideo through 29.0 contains an information disclosure vulnerability in plugin/Live/stats.json.php that allows unauthenticated attackers to retrieve stream keys and m3u8 URLs by accessing the endpoint without authentication. Attackers can enumerate private, unlisted, and group-restricted live streams by parsing the hidden_applications array in the JSON response to obtain sensitive streaming credentials.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.7
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
- CWE
- CWE-306
- Published
- 2026-09-08
- Last modified
- 2026-09-08
Affected products
- WWBN AVideo
Weakness type
Related vulnerabilities
- CVE-2026-77974 — Softish C6 Ear Camera and EarVision Android Application Missing authentication for critical function
- CVE-2026-79961 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...
- CVE-2026-11838 — Improper Authorization in Yordam Informatics' Library Reservation System
- CVE-2026-85981 — Unauthenticated Localhost Admin Panel in Auth0 AD/LDAP Connector
- CVE-2026-86464 — In the current development version of Eclipse aeriOS, for which no official release has yet been...
- CVE-2026-86808 — moltis-org moltis vault.rs vault_recovery_handler missing authentication
- CVE-2026-73004 — Windows Autopilot Tampering Vulnerability
- CVE-2026-72964 — Windows Internet Connection Sharing (ICS) Tampering Vulnerability