PT-2026-29361 · Avideo · Live Plugin+1

Adrgs

·

Published

2026-03-31

·

Updated

2026-04-01

·

CVE-2026-34731

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions AVideo versions 26.0 and prior
Description The AVideo platform, specifically the Live plugin, has an issue where the on publish done.php endpoint does not perform authentication or authorization checks. Unauthenticated users can terminate active live streams by sending crafted POST requests to this endpoint. Attackers can obtain active stream keys from the stats.json.php endpoint and use them to disrupt live broadcasts, leading to a denial-of-service against the live streaming functionality.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2026-34731
GHSA-4JCG-JXPF-5VQ3

Affected Products

Avideo
Live Plugin