CVE-2026-86721: AVideo through c3edcc274c Authorization Bypass via Session Cookie

Published Sep 8, 2026
·
Updated

AVideo through commit c3edcc274c contains an authorization bypass vulnerability where a session cookie named 'key' with value 'value' overrides the $REQUEST['key'] parameter in saveLive.php and related endpoints. Attackers can publish to any user's RTMP stream without authentication by using the known constant stream key value to hijack live broadcasts.

Affected Software

1 affected component
AVideo=c3edcc274c

Event History

Sep 8, 2026
CVE Published
via MITRE·03:13 PM
Data Sourced
via MITRE·03:13 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:18 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What does an attacker need to exploit this issue?

The attacker needs only network access to a vulnerable AVideo instance. No authentication or user interaction is required; they can use a session cookie named "key" with the value "value" as the stream key.

2

What systems or users are exposed?

AVideo instances that include the affected behavior in saveLive.php or related endpoints are exposed. Any user's RTMP stream may be targeted, allowing an unauthenticated attacker to publish content to and hijack live broadcasts.

3

How can I tell whether an instance is affected?

Review the deployed AVideo code for the behavior described through commit c3edcc274c: a session cookie named "key" with value "value" overriding the $_REQUEST['key'] parameter in saveLive.php or related endpoints. An instance exhibiting that override is affected.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203