CVE-2026-86720: WWBN AVideo Missing Authorization via resendRestreamer.json.php

Published Sep 8, 2026
·
Updated

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate ownership of liverestreamsid in resendRestreamer.json.php, allowing authenticated users with canStream to access other users' restream destinations. Attackers can broadcast their live stream to victim-configured restream destinations by supplying arbitrary liverestreamsid values, hijacking YouTube, Facebook, or Twitch streams using victim stream keys.

Affected Software

1 affected component
WWBN AVideo>undefined

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Patch c3edcc274c389816d434acadac07ee78eaf330c1

Event History

Sep 8, 2026
CVE Published
via MITRE·03:13 PM
Data Sourced
via MITRE·03:13 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:18 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An authenticated AVideo user who has the canStream permission can exploit it. The attacker does not need to own the targeted restream configuration.

2

What access does exploitation provide?

An attacker can access another user's configured restream destinations and broadcast their own live stream to them. This can hijack streams on destinations such as YouTube, Facebook, or Twitch by using the victim's stream keys.

3

What identifier does an attacker need to manipulate?

The attacker supplies arbitrary live_restreams_id values to resendRestreamer.json.php. The affected endpoint does not validate that the requester owns the referenced restream configuration.

4

How can administrators determine whether their deployment is affected?

Deployments are affected if they include the described behavior through commit c3edcc274c389816d434acadac07ee78eaf330c1. Review resendRestreamer.json.php to determine whether it verifies ownership of live_restreams_id before using a restream destination.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203