CVE-2026-68004: Ossrs SRS (Simple Realtime Server) vulnerability
An issue in OSSRS SRS (Simple Realtime Server) <v5.0.213 allows a remote attacker to execute arbitrary code via RTMP publish authorization, vhost-level security configuration (security.enabled), SrsSecurity::check(), trunk/src/app/srsappsecurity.cpp, and SRS RTMP listener components
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Mitigate the reported SRS RTMP arbitrary code execution risk by disabling the vhost-level security configuration setting `security.enabled` (security.enabled) so that `SrsSecurity::check()` is not applied via vhost security configuration.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-68004?
CVE-2026-68004 has a risk score of 81, indicating a high severity level.
How do I fix CVE-2026-68004?
To fix CVE-2026-68004, update Ossrs SRS to version 5.0.213 or later where the vulnerability is resolved.
What type of attack is possible with CVE-2026-68004?
CVE-2026-68004 allows a remote attacker to execute arbitrary code via improper RTMP publish authorization.
Which components are affected by CVE-2026-68004?
CVE-2026-68004 affects the SrsSecurity::check() function and the SRS RTMP listener components.
When was CVE-2026-68004 published?
CVE-2026-68004 was published on August 17, 2026.