Description
WWBN AVideo through 29.0 fails to enforce user-group restrictions in the plugin/Live/stats.json.php and plugin/Live/calendar.json.php endpoints. Unauthenticated attackers can retrieve restricted live transmission details including stream keys, titles, descriptions, owner information, and direct HLS playback URLs by accessing these endpoints.
Published: 2026-09-15
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized disclosure of live streaming metadata and stream keys
Action: Apply Patch
AI Analysis

Impact

WWBN AVideo fails to enforce user‑group restrictions on the Live plugin. Unauthenticated attackers can retrieve restricted live transmission details, including stream keys, titles, descriptions, owner information, and direct HLS playback URLs by accessing the plugin/Live/stats.json.php and plugin/Live/calendar.json.php endpoints. This is an information‑disclosure flaw (CWE‑200) that compromises the confidentiality of live video streams.

Affected Systems

WWBN AVideo for all platforms, versions up to and including 29.0, and any installation using the Live plugin that exposes the plugin/Live/stats.json.php or plugin/Live/calendar.json.php endpoints.

Risk and Exploitability

The CVSS score of 8.7 classifies the vulnerability as high, and the lack of authentication requirements means attackers can exploit it simply by sending HTTP requests to the vulnerable endpoints. The EPSS score of less than 1% indicates a very low but nonzero likelihood of exploitation, and the vulnerability is not listed in KEV. Effective exploitation requires only network access to the server and knowledge of the endpoint URLs.

Generated by OpenCVE AI on September 20, 2026 at 16:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to the latest WWBN AVideo release (30.0 or later) where the Live endpoint restrictions are correctly enforced.
  • If an upgrade cannot be performed immediately, disable the Live plugin or block access to the /plugin/Live/stats.json.php and /plugin/Live/calendar.json.php endpoints with the web server configuration or firewall rules.
  • Apply network segmentation or ACLs so only trusted administrative IPs can reach the Live endpoints, and monitor logs for suspicious access attempts.

Generated by OpenCVE AI on September 20, 2026 at 16:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description WWBN AVideo through 29.0 fails to enforce user-group restrictions in the plugin/Live/stats.json.php and plugin/Live/calendar.json.php endpoints. Unauthenticated attackers can retrieve restricted live transmission details including stream keys, titles, descriptions, owner information, and direct HLS playback URLs by accessing these endpoints.
Title WWBN AVideo through 29.0 Broken Access Control via Live Endpoints
First Time appeared Wwbn
Wwbn avideo
Weaknesses CWE-200
CPEs cpe:2.3:a:wwbn:avideo:*:*:*:*:*:*:*:*
Vendors & Products Wwbn
Wwbn avideo
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-15T15:59:43.801Z

Reserved: 2026-09-15T11:08:44.670Z

Link: CVE-2026-91965

cve-icon Vulnrichment

Updated: 2026-09-15T15:59:40.368Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T16:17:52.643

Modified: 2026-09-16T19:49:18.987

Link: CVE-2026-91965

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T17:00:13Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor