Vulnerability Description
WWBN AVideo through 29.0 fails to enforce user-group restrictions in the plugin/Live/stats.json.php and plugin/Live/calendar.json.php endpoints. Unauthenticated attackers can retrieve restricted live transmission details including stream keys, titles, descriptions, owner information, and direct HLS playback URLs by accessing these endpoints.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/WWBN/AVideo/security/advisories/GHSA-4xhp-wjpj-p92w
- https://www.vulncheck.com/advisories/wwbn-avideo-through-29.0-broken-access-cont
- https://github.com/WWBN/AVideo/security/advisories/GHSA-4xhp-wjpj-p92w
FAQ
What is CVE-2026-91965?
CVE-2026-91965 is a vulnerability with a CVSS score of 7.5 (HIGH). WWBN AVideo through 29.0 fails to enforce user-group restrictions in the plugin/Live/stats.json.php and plugin/Live/calendar.json.php endpoints. Unauthenticated attackers can retrieve restricted live ...
How severe is CVE-2026-91965?
CVE-2026-91965 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-91965?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.