CVE-2026-41470: LIVE555 < 2026.04.22 RTSP Server Authorization Bypass via Session Token
LIVE555 before 2026.04.22 contains an authorization bypass vulnerability in RTSP session command handling that allows attackers to replay valid Session tokens from unauthenticated connections. Attackers who obtain a valid Session token can issue PLAY and TEARDOWN commands from a second TCP connection without authentication, causing server crashes through virtual function call errors or disrupting active streams by terminating victim sessions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-41470?
CVE-2026-41470 is considered a medium severity vulnerability due to its potential to allow unauthorized access through session token replay.
How do I fix CVE-2026-41470?
To remediate CVE-2026-41470, upgrade your LIVE555 RTSP server to version 2026.04.22 or later.
What types of attacks are possible with CVE-2026-41470?
CVE-2026-41470 allows attackers to exploit an authorization bypass by replaying valid session tokens from unauthenticated sessions.
Which versions of LIVE555 are affected by CVE-2026-41470?
CVE-2026-41470 affects all versions of LIVE555 prior to 2026.04.22.
What is the impact of exploiting CVE-2026-41470?
Exploiting CVE-2026-41470 can lead to unauthorized access to RTSP streams, compromising the confidentiality and integrity of media streams.