MEDIUMVulnerability

CVE-2026-86726

AVideo through 29.0 contains an information disclosure vulnerability in restreamsActive.json.php that allows authenticated streamers to enumerate source stream keys and identities of all other streamers' active restreams. The endpoint fails to filter results by user ownership, exposing sensitive transmission credentials and streamer identity across all accounts to any user with streaming capability.

Properties

severity
MEDIUM
score
6.5
cve_id
CVE-2026-86726
signal_observed_at
2026-09-19T18:05:26+00:00
vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
published_at
2026-09-08T16:18:33.690
last_modified
2026-09-19T15:17:06.767

Related Entities (2)

HAS_WEAKNESS (1)

[Weakness]Insufficiently Protected Credentials

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-86726 — Ninja Signal Threat Intelligence | Ninja Signal