HIGHVulnerability

CVE-2026-86721

AVideo through commit c3edcc274c contains an authorization bypass vulnerability where a session cookie named 'key' with value 'value' overrides the $_REQUEST['key'] parameter in saveLive.php and related endpoints. Attackers can publish to any user's RTMP stream without authentication by using the known constant stream key value to hijack live broadcasts.

Properties

severity
HIGH
score
7.5
cve_id
CVE-2026-86721
signal_observed_at
2026-09-19T18:05:26+00:00
vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
published_at
2026-09-08T16:18:32.307
last_modified
2026-09-19T15:17:06.637

Related Entities (2)

HAS_WEAKNESS (1)

[Weakness]Improper Authentication

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-86721 — Ninja Signal Threat Intelligence | Ninja Signal