AVideo through commit c3edcc274c contains an authorization bypass vulnerability where a session cookie named 'key' with value 'value' overrides the $_REQUEST['key'] parameter in saveLive.php and related endpoints. Attackers can publish to any user's RTMP stream without authentication by using the known constant stream key value to hijack live broadcasts.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-08 16:18
Updated : 2026-09-08 19:53
NVD link : CVE-2026-86721
Mitre link : CVE-2026-86721
CVE.ORG link : CVE-2026-86721
JSON object : View
Products Affected
No product.
CWE
CWE-287
Improper Authentication
