Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-88865

Опубликовано: 10 сент. 2026
Источник: nvd
CVSS3: 8.1
EPSS Низкий

Описание

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate restream ownership in getRestream.json.php, allowing authenticated users with canStream permission to mint tokens for arbitrary restreams. Attackers can exchange the token to retrieve other users' stream keys from getLiveKey.json.php and publish to their YouTube, Twitch, or RTMP destinations.

EPSS

Процентиль: 18%
0.00258
Низкий

8.1 High

CVSS3

Дефекты

CWE-639

Связанные уязвимости

CVSS3: 8.1
github
13 дней назад

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate restream ownership in getRestream.json.php, allowing authenticated users with canStream permission to mint tokens for arbitrary restreams. Attackers can exchange the token to retrieve other users' stream keys from getLiveKey.json.php and publish to their YouTube, Twitch, or RTMP destinations.

EPSS

Процентиль: 18%
0.00258
Низкий

8.1 High

CVSS3

Дефекты

CWE-639