ZeroHour

CVE-2026-91965

moderate

Unauthenticated Stream Key Disclosure in WWBN AVideo Live Plugin Endpoints

CVSS 4.0
8.7 high
EPSS
Published
()
Modified
AI analysis

WWBN AVideo through version 29.0 fails to enforce user-group restrictions on two Live plugin JSON endpoints, plugin/Live/stats..php and plugin/Live/calendar..php. Any unauthenticated remote attacker can request these endpoints directly to retrieve details of restricted live transmissions, including stream keys, titles, descriptions, owner information, and direct HLS playback URLs. Leaked stream keys can allow an attacker to hijack the ingest and broadcast over the legitimate channel, while the HLS URLs enable unauthorized viewing of restricted streams. All self-hosted AVideo deployments through 29.0 that expose the Live plugin are affected. No public proof of concept is known and the flaw is not in the CISA KEV catalog, so exploitation status is currently none known.

What to do: Upgrade to an AVideo release newer than 29.0 as soon as the vendor ships a fix. In the interim, block or require authentication for the plugin/Live/stats..php and plugin/Live/calendar..php endpoints at the reverse proxy or WAF. Rotate all live stream keys and review web server access logs for unauthenticated hits against these two endpoints to identify potential prior data exposure.

Affected
WWBN AVideothrough 29.0
Estimated exposure
moderate≈1,000–5,000 internet-exposed self-hosted AVideo servers — AVideo is a niche self-hosted video platform whose instances are fingerprintable in public internet-wide scans (e.g., Shodan), which historically show low-thousands of exposed deployments; this is a rough order-of-magnitude estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

WWBN AVideo through 29.0 fails to enforce user-group restrictions in the plugin/Live/stats.json.php and plugin/Live/calendar.json.php endpoints. Unauthenticated attackers can retrieve restricted live transmission details including stream keys, titles, descriptions, owner information, and direct HLS playback URLs by accessing these endpoints.

Weakness
CWE-200
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.