SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-86727

HIGH · CVSS 7.5 EPSS 0.31% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-08 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

AVideo versions up to 29.0 are vulnerable to an information disclosure flaw in the stats.json.php endpoint, allowing unauthenticated attackers to access sensitive stream keys and m3u8 URLs. This vulnerability enables the enumeration of private and restricted live streams, potentially exposing sensitive streaming credentials. Organizations using AVideo should prioritize patching this vulnerability to protect their streaming content and user privacy.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-86727
Severity
HIGH
CVSS
7.5
EPSS
0.31%

Original NVD Description

AVideo through 29.0 contains an information disclosure vulnerability in plugin/Live/stats.json.php that allows unauthenticated attackers to retrieve stream keys and m3u8 URLs by accessing the endpoint without authentication. Attackers can enumerate private, unlisted, and group-restricted live streams by parsing the hidden_applications array in the JSON response to obtain sensitive streaming credentials.