AUGUST 14, 2026
Live Feed
Back to database
Case File

CVE-2026-73039

MEDIUM · CVSS 5.4 EPSS 0.22% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-13 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

The vulnerability in ViewingStatusController allows authenticated users to exploit insecure direct object references, enabling them to read and delete other users' viewing status records. This could lead to unauthorized access to sensitive user data, manipulation of viewing history, and disruption of the "Continue Watching" feature. Organizations using the affected products should prioritize remediation to protect user privacy and maintain the integrity of their services.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-73039
Severity
MEDIUM
CVSS
5.4
EPSS
0.22%

Original NVD Description

streama contains an insecure direct object reference vulnerability in ViewingStatusController that allows authenticated users to read and delete other users' viewing status records. Attackers can enumerate all users' watch progress, delete arbitrary viewing history, and manipulate other users' Continue Watching dashboards by supplying arbitrary primary keys without ownership verification.