CVE-2026-89252

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to verify ownership in addLiveLink.php when updating LiveLinks, allowing authenticated users to modify other users' links. A canStream user can overwrite another user's LiveLink HLS source and metadata by supplying an existing linkId, redirecting viewers to attacker-controlled media.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-11 12:16

Updated : 2026-09-15 17:17


NVD link : CVE-2026-89252

Mitre link : CVE-2026-89252

CVE.ORG link : CVE-2026-89252


JSON object : View

Products Affected

No product.

CWE
CWE-639

Authorization Bypass Through User-Controlled Key