CVE-2026-86728: AVideo through 29.0 Unauthenticated Disclosure via epg.json.php
AVideo through 29.0 contains an authentication bypass vulnerability in plugin/PlayLists/epg.json.php that exposes live-stream keys and private EPG schedules to unauthenticated users. Attackers can request the endpoint with sequential user or playlist IDs to retrieve sensitive credentials, server identifiers, and complete programme schedules without authentication.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
AVideo installations through version 29.0 are affected if the PlayLists plugin endpoint plugin/PlayLists/epg.json.php is reachable by unauthenticated users. The issue can expose live-stream keys, private EPG schedules, server identifiers, and programme schedules.
What does an attacker need to exploit it?
No authentication, privileges, or user interaction are required. An attacker can request the affected endpoint and enumerate sequential user or playlist IDs to retrieve data.
How can I check whether information may already be exposed?
Review access logs for unauthenticated requests to plugin/PlayLists/epg.json.php, particularly requests using sequential user or playlist IDs. Such requests may indicate attempts to enumerate and retrieve stream credentials or EPG data.