PT-2026-76773 · Git · Srs

CVE-2026-68004

·

Published

2026-08-17

·

Updated

2026-08-17

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OSSRS SRS (Simple Realtime Server) versions prior to 5.0.213
Description A remote attacker can execute arbitrary code through the SRS RTMP listener components. The issue involves the RTMP publish authorization process, specifically within the vhost-level security configuration security.enabled, the SrsSecurity::check() function, and the trunk/src/app/srs app security.cpp file.
Recommendations Update OSSRS SRS (Simple Realtime Server) to version 5.0.213 or later.

Exploit

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-68004

Affected Products

Srs