High severity7.5NVD Advisory· Published Sep 15, 2026· Updated Sep 15, 2026
CVE-2026-91965
CVE-2026-91965
Description
WWBN AVideo through 29.0 fails to enforce user-group restrictions in the plugin/Live/stats.json.php and plugin/Live/calendar.json.php endpoints. Unauthenticated attackers can retrieve restricted live transmission details including stream keys, titles, descriptions, owner information, and direct HLS playback URLs by accessing these endpoints.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.