Description
AVideo through 29.0 contains an authentication bypass vulnerability in plugin/PlayLists/epg.json.php that exposes live-stream keys and private EPG schedules to unauthenticated users. Attackers can request the endpoint with sequential user or playlist IDs to retrieve sensitive credentials, server identifiers, and complete programme schedules without authentication.
Published: 2026-09-08
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Confidentiality Disclosure via Authentication Bypass
Action: Assess Impact
AI Analysis

Impact

AVideo releases up through version 29.0 allow unauthenticated users to send requests to the plugin/PlayLists/epg.json.php endpoint and retrieve sensitive data, including live‑stream keys, private Electronic Program Guide schedules, server identifiers, and user or playlist identifiers. The flaw is an authentication bypass that enables sequential probing of numeric identifiers to expose confidential streaming content and network topology. This vulnerability directly compromises content confidentiality and potentially reveals internal infrastructure details.

Affected Systems

All installations of the open‑source AVideo media platform from WWBN running versions 29.0 or earlier contain the vulnerable epg.json.php script. Any site that includes the PlayLists/epg.json.php component is at risk until a fix is issued.

Risk and Exploitability

The CVSS score of 8.7 classifies the vulnerability as high severity, and the lack of authentication requirements makes the exploit trivial over the network. Although an EPSS score is unavailable, the flaw’s simplicity and public disclosure suggest a realistic exploitation risk. Attackers can enumerate the endpoint with sequential numeric identifiers to extract private data, presenting a clear pathway for information theft. The vulnerability is not listed in CISA’s KEV catalog, but the impact remains significant for any deployed version.

Generated by OpenCVE AI on September 8, 2026 at 16:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Restrict access to the epg.json.php endpoint through firewall or web server configuration to require authentication when the endpoint is invoked.
  • If the EPG functionality is not needed, disable or remove the PlayLists/epg.json.php module to eliminate the attack surface.
  • Monitor the vendor’s security advisories and apply any future patch or fix promptly when it becomes available.

Generated by OpenCVE AI on September 8, 2026 at 16:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description AVideo through 29.0 contains an authentication bypass vulnerability in plugin/PlayLists/epg.json.php that exposes live-stream keys and private EPG schedules to unauthenticated users. Attackers can request the endpoint with sequential user or playlist IDs to retrieve sensitive credentials, server identifiers, and complete programme schedules without authentication.
Title AVideo through 29.0 Unauthenticated Disclosure via epg.json.php
First Time appeared Wwbn
Wwbn avideo
Weaknesses CWE-306
CPEs cpe:2.3:a:wwbn:avideo:*:*:*:*:*:*:*:*
Vendors & Products Wwbn
Wwbn avideo
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-08T15:32:45.058Z

Reserved: 2026-09-08T11:31:09.013Z

Link: CVE-2026-86728

cve-icon Vulnrichment

Updated: 2026-09-08T15:32:35.899Z

cve-icon NVD

Status : Deferred

Published: 2026-09-08T16:18:33.983

Modified: 2026-09-08T19:53:13.400

Link: CVE-2026-86728

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T17:00:02Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function