SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-86720

HIGH · CVSS 8.1 EPSS 0.26% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-08 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The vulnerability allows authenticated users with streaming permissions to exploit the resendRestreamer.json.php file, enabling them to access and hijack other users' configured restream destinations by manipulating the live_restreams_id parameter. This can lead to unauthorized broadcasting of live streams on platforms like YouTube, Facebook, or Twitch, potentially compromising the victim's stream integrity and audience. Organizations utilizing the affected AVideo platform should prioritize addressing this issue to safeguard their streaming operations and user privacy.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-86720
Severity
HIGH
CVSS
8.1
EPSS
0.26%

Original NVD Description

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate ownership of live_restreams_id in resendRestreamer.json.php, allowing authenticated users with canStream to access other users' restream destinations. Attackers can broadcast their live stream to victim-configured restream destinations by supplying arbitrary live_restreams_id values, hijacking YouTube, Facebook, or Twitch streams using victim stream keys.