No analysis available yet.
No remediation available yet.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 15 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 15 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | WWBN AVideo through 29.0 fails to enforce user-group restrictions in the plugin/Live/stats.json.php and plugin/Live/calendar.json.php endpoints. Unauthenticated attackers can retrieve restricted live transmission details including stream keys, titles, descriptions, owner information, and direct HLS playback URLs by accessing these endpoints. | |
| Title | WWBN AVideo through 29.0 Broken Access Control via Live Endpoints | |
| First Time appeared |
Wwbn
Wwbn avideo |
|
| Weaknesses | CWE-200 | |
| CPEs | cpe:2.3:a:wwbn:avideo:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Wwbn
Wwbn avideo |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-15T15:59:43.801Z
Reserved: 2026-09-15T11:08:44.670Z
Link: CVE-2026-91965
Updated: 2026-09-15T15:59:40.368Z
Status : Received
Published: 2026-09-15T16:17:52.643
Modified: 2026-09-15T17:17:42.600
Link: CVE-2026-91965
No data.
OpenCVE Enrichment
Updated: 2026-09-15T17:45:17Z
-
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor