PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-88865 WWBN CVE debrief

AVideo fails to validate restream ownership, allowing authenticated users with canStream permission to mint tokens for arbitrary restreams. This could lead to unauthorized publishing to YouTube, Twitch, or RTMP destinations and potential disclosure of stream keys. Defenders should assess exposure, prioritize verification and remediation efforts, and monitor for suspicious activity. AVideo instances require verification of configurations and user permissions to prevent exploitation. The vulnerability exists in AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1, affecting authenticated users with canStream permission.

Vendor
WWBN
Product
AVideo
CVSS
HIGH 8.6
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-10
Original CVE updated
2026-09-18
Advisory published
2026-09-10
Advisory updated
2026-09-18

Who should care

Defenders responsible for AVideo instances, security teams, and administrators should assess exposure and prioritize verification and remediation efforts. AVideo users with canStream permission, security personnel, and IT teams managing AVideo instances should be aware of the vulnerability and take necessary precautions. Security teams should monitor for suspicious activity and implement compensating controls to detect potential exploitation.

Why it matters

AVideo's failure to validate restream ownership allows authenticated users to mint tokens for arbitrary restreams, potentially leading to unauthorized publishing and stream key disclosure. Defenders should prioritize verification, restrict user permissions, and monitor for suspicious activity.

  • Potential unauthorized publishing to YouTube, Twitch, or RTMP destinations.
  • Possible retrieval of other users' stream keys from getLiveKey.json.php.
  • Required verification of AVideo configurations and user permissions.
  • Need for monitoring and compensating controls to detect suspicious activity.

Technical summary

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate restream ownership in getRestream.json.php, allowing authenticated users with canStream permission to mint tokens for arbitrary restreams. This could lead to unauthorized publishing to YouTube, Twitch, or RTMP destinations and potential disclosure of stream keys. The vulnerability requires verification of AVideo configurations and user permissions to prevent exploitation. Defenders should prioritize verifying AVideo configurations, restricting user permissions, and monitoring for suspicious activity.

Defensive priority

Defenders should prioritize verifying AVideo configurations, restricting user permissions, and monitoring for suspicious activity.

Recommended defensive actions

  • Verify AVideo configurations and restrict user permissions to prevent unauthorized restream token minting.
  • Monitor for suspicious activity and implement compensating controls to detect potential exploitation.
  • Review and update AVideo instances to ensure proper authorization and authentication mechanisms are in place.
  • Perform vulnerability assessment and penetration testing to identify potential entry points.
  • Implement additional security controls, such as IP restrictions and access logging.
  • Conduct regular security audits and risk assessments to identify vulnerabilities.
  • Develop an incident response plan in case of potential exploitation.

Evidence notes

The CVE record and NVD entry provide details on the vulnerability. Additional information on affected versions, remediation, and verification steps is needed. Defenders should verify AVideo configurations, restrict user permissions, and monitor for suspicious activity. The vulnerability allows authenticated users to mint tokens for arbitrary restreams, potentially leading to unauthorized publishing and stream key disclosure.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-88865 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-88865

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-88865 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-88865

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.