Description
AVideo through 29.0 contains an information disclosure vulnerability in restreamsActive.json.php that allows authenticated streamers to enumerate source stream keys and identities of all other streamers' active restreams. The endpoint fails to filter results by user ownership, exposing sensitive transmission credentials and streamer identity across all accounts to any user with streaming capability.
Published: 2026-09-08
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in the restreamsActive.json.php endpoint allows an authenticated streamer to retrieve the source stream keys and identities of all active restreams owned by other users. This results in an unintended disclosure of transmission credentials and the identities of streamers across accounts, exposing sensitive data that should be protected by the application.

Affected Systems

AVideo software produced by WWBN versions 29.0 and earlier are affected. No specific patch level is indicated in the advisory, so any deployment using AVideo 29.0 or an older release will contain the flaw.

Risk and Exploitability

The CVSS score of 7.1 indicates a moderate to high severity risk. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. The attack vector requires an attacker to be logged in with streamer privileges; once authenticated, the attacker can enumerate all active streams of other streamers. Because the source stream keys are disclosed, an adversary could tap into or hijack other users’ live streams, representing a significant confidentiality breach.

Generated by OpenCVE AI on September 8, 2026 at 17:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade AVideo to a release newer than 29.0 or apply the vendor‑supplied patch that corrects the endpoint filtering flaw.
  • Configure the application or web server to restrict access to restreamsActive.json.php so that only the authenticated user can view their own active restreams, enforcing user‑based filtering or role‑based access control.
  • If an immediate upgrade is not possible, temporarily disable or block access to restreamsActive.json.php for non‑administrator users until the patch is applied.

Generated by OpenCVE AI on September 8, 2026 at 17:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description AVideo through 29.0 contains an information disclosure vulnerability in restreamsActive.json.php that allows authenticated streamers to enumerate source stream keys and identities of all other streamers' active restreams. The endpoint fails to filter results by user ownership, exposing sensitive transmission credentials and streamer identity across all accounts to any user with streaming capability.
Title AVideo through 29.0 Information Disclosure via restreamsActive.json.php
First Time appeared Wwbn
Wwbn avideo
Weaknesses CWE-522
CPEs cpe:2.3:a:wwbn:avideo:*:*:*:*:*:*:*:*
Vendors & Products Wwbn
Wwbn avideo
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-08T15:13:58.217Z

Reserved: 2026-09-08T11:30:41.420Z

Link: CVE-2026-86726

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-08T16:18:33.690

Modified: 2026-09-08T19:53:13.400

Link: CVE-2026-86726

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T17:15:17Z

Weaknesses
  • CWE-522

    Insufficiently Protected Credentials