CVE-2026-86727: Missing Authentication for Critical Function in WWBN AVideo
AVideo versions through 29.0 have an information disclosure vulnerability in the plugin/Live/stats.json.php endpoint. This flaw allows unauthenticated attackers to access sensitive streaming credentials such as stream keys and m3u8 URLs. Attackers can enumerate private, unlisted, and group-restricted live streams by parsing the hidden_applications array in the JSON response. The vulnerability has a high severity with a CVSS score of 8.7. No official patch or remediation guidance is currently available from the vendor.
AI Analysis
Technical Summary
CVE-2026-86727 is an information disclosure vulnerability in WWBN AVideo through version 29.0. The vulnerability exists in the plugin/Live/stats.json.php endpoint, which does not require authentication. This allows unauthenticated attackers to retrieve sensitive streaming credentials including stream keys and m3u8 URLs. Additionally, attackers can enumerate private, unlisted, and group-restricted live streams by analyzing the hidden_applications array in the JSON response. The vulnerability has a CVSS 4.0 base score of 8.7, indicating high severity. There is no vendor advisory or patch information available at this time.
Potential Impact
An attacker can obtain sensitive streaming credentials without authentication, including stream keys and m3u8 URLs. This exposure can lead to unauthorized access to private, unlisted, and group-restricted live streams. The confidentiality of streaming content is compromised, potentially leading to unauthorized viewing or redistribution.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict access to the vulnerable endpoint by implementing authentication or network-level controls to prevent unauthenticated access to plugin/Live/stats.json.php.
CVE-2026-86727: Missing Authentication for Critical Function in WWBN AVideo
Description
AVideo versions through 29.0 have an information disclosure vulnerability in the plugin/Live/stats.json.php endpoint. This flaw allows unauthenticated attackers to access sensitive streaming credentials such as stream keys and m3u8 URLs. Attackers can enumerate private, unlisted, and group-restricted live streams by parsing the hidden_applications array in the JSON response. The vulnerability has a high severity with a CVSS score of 8.7. No official patch or remediation guidance is currently available from the vendor.
CVSS v4.0
Score 8.7high
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-86727 is an information disclosure vulnerability in WWBN AVideo through version 29.0. The vulnerability exists in the plugin/Live/stats.json.php endpoint, which does not require authentication. This allows unauthenticated attackers to retrieve sensitive streaming credentials including stream keys and m3u8 URLs. Additionally, attackers can enumerate private, unlisted, and group-restricted live streams by analyzing the hidden_applications array in the JSON response. The vulnerability has a CVSS 4.0 base score of 8.7, indicating high severity. There is no vendor advisory or patch information available at this time.
Potential Impact
An attacker can obtain sensitive streaming credentials without authentication, including stream keys and m3u8 URLs. This exposure can lead to unauthorized access to private, unlisted, and group-restricted live streams. The confidentiality of streaming content is compromised, potentially leading to unauthorized viewing or redistribution.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict access to the vulnerable endpoint by implementing authentication or network-level controls to prevent unauthenticated access to plugin/Live/stats.json.php.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-09-08T11:30:41.420Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6aa029bfacd9273b49d8b68c
Added to database: 09/08/2026, 15:29:03 UTC
Last enriched: 09/08/2026, 15:38:07 UTC
Last updated: 09/09/2026, 01:31:23 UTC
Views: 9
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.