PatchSiren

streamaserver CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM streamaserver CVE published 2026-08-13

CVE-2026-73039

CVE-2026-73039 is a medium-severity vulnerability in streama that allows authenticated users to read and delete other users' viewing status records. The vulnerability is caused by an insecure direct object reference in ViewingStatusController. Attackers can exploit this vulnerability to enumerate all users' watch progress, delete arbitrary viewing history, and manipulate other users' Continue Watching dashboards.