CVE-2026-91965
moderateUnauthenticated Stream Key Disclosure in WWBN AVideo Live Plugin Endpoints
WWBN AVideo through version 29.0 fails to enforce user-group restrictions on two Live plugin JSON endpoints, plugin/Live/stats..php and plugin/Live/calendar..php. Any unauthenticated remote attacker can request these endpoints directly to retrieve details of restricted live transmissions, including stream keys, titles, descriptions, owner information, and direct HLS playback URLs. Leaked stream keys can allow an attacker to hijack the ingest and broadcast over the legitimate channel, while the HLS URLs enable unauthorized viewing of restricted streams. All self-hosted AVideo deployments through 29.0 that expose the Live plugin are affected. No public proof of concept is known and the flaw is not in the CISA KEV catalog, so exploitation status is currently none known.
What to do: Upgrade to an AVideo release newer than 29.0 as soon as the vendor ships a fix. In the interim, block or require authentication for the plugin/Live/stats..php and plugin/Live/calendar..php endpoints at the reverse proxy or WAF. Rotate all live stream keys and review web server access logs for unauthenticated hits against these two endpoints to identify potential prior data exposure.
| WWBN AVideo | through 29.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
WWBN AVideo through 29.0 fails to enforce user-group restrictions in the plugin/Live/stats.json.php and plugin/Live/calendar.json.php endpoints. Unauthenticated attackers can retrieve restricted live transmission details including stream keys, titles, descriptions, owner information, and direct HLS playback URLs by accessing these endpoints.
- Weakness
- CWE-200
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.