CVE-2026-89250: WWBN AVideo Unauthenticated File Read via getRecordedFile.php
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains an unauthenticated file read vulnerability in the getRecordedFile.php endpoint that streams recorded FLV files from the temporary directory. Attackers can request the endpoint with a known or guessed stream key to download recorded live video files without authentication or authorization checks.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
AVideo deployments that expose the getRecordedFile.php endpoint and retain recorded FLV files in the temporary directory are exposed. An attacker does not need an account or any authentication.
What does an attacker need to retrieve a recording?
The attacker needs a known or guessed stream key and network access to the affected endpoint. Exploitation is low complexity and does not require user interaction.
What is the impact of successful exploitation?
An attacker can download recorded live-video FLV files from the temporary directory. The reported impact is high confidentiality impact, with no stated integrity or availability impact.