PT-2026-25732 · Wowza · Streaming Engine

Published

2026-03-15

·

Updated

2026-03-16

·

CVE-2016-20034

CVSS v3.1

8.0

High

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Wowza Streaming Engine version 4.5.0
Description Wowza Streaming Engine 4.5.0 contains a condition that allows authenticated users with read-only access to gain administrative privileges. This is achieved by manipulating parameters within POST requests sent to the user edit endpoint. Specifically, attackers can set the accessLevel parameter to 'admin' and the advUser parameters to 'true' and 'on' to obtain administrative access.
Recommendations Apply any available updates or patches to address this issue. As a temporary workaround, restrict access to the user edit endpoint to prevent unauthorized modification of user privileges.

Exploit

Fix

LPE

CSRF

Weakness Enumeration

Related Identifiers

CVE-2016-20034

Affected Products

Streaming Engine