MEDIUM
streamaserver
CVE published 2026-08-13
CVE-2026-73039
CVE-2026-73039 is a medium-severity vulnerability in streama that allows authenticated users to read and delete other users' viewing status records. The vulnerability is caused by an insecure direct object reference in ViewingStatusController. Attackers can exploit this vulnerability to enumerate all users' watch progress, delete arbitrary viewing history, and manipulate other users' Continue Watching dashboards.