SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-88874

HIGH · CVSS 7.5 EPSS 0.51% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-10 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

AVideo versions up to the specified revision are vulnerable due to insufficient enforcement of live stream password checks, allowing unauthenticated access to sensitive stream information, including RTMP stream keys and HLS URLs. This vulnerability enables remote attackers to access and view password-protected live transmissions without authorization. Organizations using AVideo with Nginx should prioritize addressing this issue to prevent unauthorized access to their live streaming content.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-88874
Severity
HIGH
CVSS
7.5
EPSS
0.51%
Nginx

Original NVD Description

AVideo through revision c3edcc274c389816d434acadac07ee78eaf330c1 (master, 2026-08-23) does not enforce the Live stream password check on the stats endpoint or on the HLS origin. Live::_getStats() (plugin/Live/Live.php) returns a password-protected transmission's RTMP stream key, its isPasswordProtected flag, and its HLS (m3u8) URL to unauthenticated callers, in both the public applications list and the hidden_applications branch used when canSeeLiveFromLiveKey() fails. Separately, the shipped NGINX configuration (deploy/nginx/nginx.conf) serves the .m3u8 playlist, the AES-128 key, and the transport-stream segments from the /live location without any auth_request (the auth_key_check directive in the .key location is commented out). A remote, unauthenticated attacker can therefore retrieve the stream key and decryption key and watch a password-protected live transmission without supplying the configured password. No patched version was available at the time of the advisory.