PT-2026-28624 · Wwbn · Avideo

Adrgs

·

Published

2026-03-27

·

Updated

2026-03-28

·

CVE-2026-34374

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions WWBN AVideo versions up to and including 26.0
Description WWBN AVideo is an open source video platform. In versions up to and including 26.0, the Live schedule::keyExists() method builds a SQL query by directly inserting a stream key into the query string without proper parameterization. This occurs as a fallback mechanism from LiveTransmition::keyExists() when the primary, parameterized lookup fails. This bypasses the security measures of the initial lookup. The issue targets the stream key lookup used during RTMP publish authentication. Attackers may be able to access the entire user database through live streams. The Live schedule::keyExists() function is vulnerable.
Recommendations Versions up to and including 26.0 should be updated when a patched version becomes available. As a temporary workaround, consider disabling the Live schedule::keyExists() function until a patch is available.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-34374
GHSA-XGV5-66WP-CH88

Affected Products

Avideo