AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to verify ownership in addLiveLink.php when updating LiveLinks, allowing authenticated users to modify other users' links. A canStream user can overwrite another user's LiveLink HLS source and metadata by supplying an existing linkId, redirecting viewers to attacker-controlled media.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-11 12:16
Updated : 2026-09-15 17:17
NVD link : CVE-2026-89252
Mitre link : CVE-2026-89252
CVE.ORG link : CVE-2026-89252
JSON object : View
Products Affected
No product.
CWE
CWE-639
Authorization Bypass Through User-Controlled Key
