CVE-2026-33716
Description
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the standalone live stream control endpoint at plugin/Live/standAloneFiles/control.json.php accepts a user-supplied streamerURL parameter that overrides where the server sends token verification requests. An attacker can redirect token verification to a server they control that always returns {"error": false}, completely bypassing authentication. This grants unauthenticated control over any live stream on the platform, including dropping active publishers, starting/stopping recordings, and probing stream existence. Commit 388fcd57dbd16f6cb3ebcdf1d08cf2b929941128 contains a patch.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
wwbn/avideoPackagist | <= 26.0 | — |
Affected products
3Patches
Vulnerability mechanics
References
4- github.com/WWBN/AVideo/commit/388fcd57dbd16f6cb3ebcdf1d08cf2b929941128nvdPatchWEB
- github.com/WWBN/AVideo/security/advisories/GHSA-9hv9-gvwm-95f2nvdExploitVendor AdvisoryWEB
- github.com/advisories/GHSA-9hv9-gvwm-95f2ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-33716ghsaADVISORY
News mentions
0No linked articles in our index yet.