PatchSiren cyber security CVE debrief
CVE-2026-86721 WWBN CVE debrief
AVideo through commit c3edcc274c contains an authorization bypass vulnerability where a session cookie named 'key' with value 'value' overrides the $_REQUEST['key'] parameter in saveLive.php and related endpoints. Attackers can publish to any user's RTMP stream without authentication by using the known constant stream key value to hijack live broadcasts.
- Vendor
- WWBN
- Product
- AVideo
- CVSS
- HIGH 8.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-08
- Original CVE updated
- 2026-09-19
- Advisory published
- 2026-09-08
- Advisory updated
- 2026-09-19
Who should care
Defenders responsible for AVideo installations, security teams assessing exposure to unauthorized stream publishing, and administrators of live broadcast services should be aware of this vulnerability and take steps to verify exposure and apply mitigations.
Why it matters
The CVE-2026-86721 authorization bypass vulnerability in AVideo allows attackers to hijack live broadcasts and publish to any user's RTMP stream without authentication. Defenders should prioritize verifying exposure, assessing impact, and applying patches or mitigations. This vulnerability has a CVSS score of 8.7 and is considered HIGH severity.
- Potential hijacking of live broadcasts
- Unauthorized publishing to RTMP streams
- Bypass of authentication mechanisms
- Possible disruption of live streaming services
Technical summary
The vulnerability exists in AVideo through commit c3edcc274c, where a session cookie named 'key' with value 'value' overrides the $_REQUEST['key'] parameter in saveLive.php and related endpoints. This allows attackers to publish to any user's RTMP stream without authentication by using the known constant stream key value to hijack live broadcasts. Defenders should prioritize verifying exposure of AVideo installations to unauthorized stream publishing, assessing the impact of potential hijacking of live broadcasts, and applying patches or mitigations as available. The CVE record and NVD entry provide details on the authorization bypass vulnerability in AVideo, including its CVSS score and vector.
Defensive priority
Defenders should prioritize verifying exposure of AVideo installations to unauthorized stream publishing, assessing the impact of potential hijacking of live broadcasts, and applying patches or mitigations as available.
Recommended defensive actions
- Verify AVideo installations for exposure to unauthorized stream publishing
- Assess the impact of potential hijacking of live broadcasts
- Apply patches or mitigations as available
- Monitor for suspicious activity related to RTMP streams
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
The CVE record and NVD entry provide details on the authorization bypass vulnerability in AVideo, including its CVSS score and vector. However, the corpus does not establish versions, exploitation, impact, or remediation beyond vendor advisories.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-86721 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-86721
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-86721 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-86721
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/WWBN/AVideo/security/advisories/GHSA-5664-h9h4-3gwc
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/avideo-through-c3edcc274c-authorization-bypass-via-session-cookie
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.