PT-2026-92084 · Wwbn · Avideo

·

CVE-2026-91965

·

Published

2026-09-15

·

Updated

2026-09-16

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions WWBN AVideo versions prior to 29.1
Description Failure to enforce user-group restrictions allows unauthenticated attackers to retrieve restricted live transmission details. This information includes stream keys, titles, descriptions, owner information, and direct HLS (HTTP Live Streaming) playback URLs. The issue occurs when accessing the 'plugin/Live/stats.json.php' and 'plugin/Live/calendar.json.php' endpoints.
Recommendations Update WWBN AVideo to a version later than 29.0. Restrict access to the 'plugin/Live/stats.json.php' and 'plugin/Live/calendar.json.php' endpoints to minimize the risk of exploitation.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-91965
GHSA-4XHP-WJPJ-P92W

Affected Products

Avideo