216.73.217.22

CVE-2026-40907

· Published 21/04/2026 20:17 · Modified 22/04/2026 21:24

Labels: CVE-2026-40907 2026-04-21CVE-2026-40907CWE-639[email protected]

Essential information

Published
21/04/2026 20:17
Modified
22/04/2026 21:24
Author
Creator
CVSS
6.5 MEDIUM (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CVSS metrics

Description

WWBN AVideo is an open source video platform. In versions 29.0 and prior, the endpoint `plugin/Live/view/Live_restreams/list.json.php` contains an Insecure Direct Object Reference (IDOR) vulnerability that allows any authenticated user with streaming permission to retrieve other users' live restream configurations, including third-party platform stream keys and OAuth tokens (access_token, refresh_token) for services like YouTube Live, Facebook Live, and Twitch. Commit d5992fff2811df4adad1d9fc7d0a5837b882aed7 fixes the issue.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
wwbn / avideo cpe:2.3:a:wwbn:avideo:29.0:*:*:*:*:*:*:*
wwbn / avideo cpe:2.3:a:wwbn:avideo:*:*:*:*:*:*:*:*

References