PT-2026-34061 · Wwbn · Avideo

Published

2026-04-14

·

Updated

2026-04-21

·

CVE-2026-40907

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions WWBN AVideo versions 29.0 and earlier
Description An Insecure Direct Object Reference (IDOR) exists in the endpoint 'plugin/Live/view/Live restreams/list.json.php'. This allows any authenticated user with streaming permissions to retrieve live restream configurations of other users. Exposed data includes third-party platform stream keys and OAuth tokens, specifically access token and refresh token, for services such as YouTube Live, Facebook Live, and Twitch.
Recommendations Update to a version that includes commit d5992fff2811df4adad1d9fc7d0a5837b882aed7.

Exploit

Fix

IDOR

Weakness Enumeration

Related Identifiers

CVE-2026-40907
GHSA-GPGP-W4X2-H3H7

Affected Products

Avideo