CVE-2026-33716Disclosure(wwbn / avideo)

LOWCVSS 9.4 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch wwbn avideo systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the standalone live stream control endpoint at `plugin/Live/standAloneFiles/control.json.php` accepts a user-supplied `streamerURL` parameter that overrides where the server sends token verification requests. An attacker can redirect token verification to a server they control that always returns `{"error": false}`, completely bypassing authentication. This grants unauthenticated control over any live stream on the platform, including dropping active publishers, starting/stopping recordings, and probing stream existence. Commit 388fcd57dbd16f6cb3ebcdf1d08cf2b929941128 contains a patch.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • avideo

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 5 classified signals
  • Peaked 2d ago at 3 mentions (2026-03-23); latest day: 2
  • 6 total mentions across 3 days

Affected systems

Vendors
Products
avideo

Deep dive

Activity timeline6 mentions / 3d
01223Mentions · 2026-03-23: 3Mentions · 2026-03-24: 1Mentions · 2026-03-27: 2Patch / Workaround · 2026-03-23: 1Patch / Workaround · 2026-03-27: 1Technical Details · 2026-03-23: 2Technical Details · 2026-03-24: 1Technical Details · 2026-03-27: 103-2303-2403-27
Signal classification2 categories
Disclosure
583.3%
Patch
116.7%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-233
Disclosure2Patch1
2026-03-241
Disclosure1
2026-03-272
Disclosure2
Full discourse6 posts
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-33716 - AVideo Allows Unauthenticated Live Stream Control via Token Verification URL Override in control.json.php Intel Report: https://ift.tt/H34t1Nw

    Post summary

    An alert announces CVE-2026-33716, describing unauthenticated live‑stream control via token override in AVideo. No PoC, exploit, patch, or active exploitation details are provided.

    0001038
    289 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    An unauthenticated live stream control vulnerability (CVE-2026-33716) affects `AVideo`. This flaw allows manipulation of live broadcasts. Admins should monitor for patches. #AVideo #livestream #infosec https://www.pulsepatch.io/posts/cve-2026-33716-avideo-unauthenticated-live-stream-control

    Post summary

    CVE-2026-33716 is an unauthenticated live stream control vulnerability in AVideo that enables manipulation of live broadcasts; administrators are advised to watch for forthcoming patches.

    0000027
    6 followersView on X
  • Vulert@vulert_official
    Disclosure

    🚨🚨 Critical AVideo flaw CVE-2026-33716 could allow unauthorized control of live streams, putting streaming platforms at serious risk. 🔗 https://vulert.com/vuln-db/CVE-2026-33716 🛡️ #CyberSecurity #AVideo #LiveStreamingSecurity #CVE202633716 #AppSec #DevSecOps #OpenSourceSecurity https://t.co/PiQ5YuetVw

    Post summary

    The tweet announces a critical CVE (CVE-2026-33716) that could enable unauthorized control of live streams, with no PoC, exploit, or patch details provided.

    0000034
    122 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-33716: AVideo Allows Unauthenticated Li... AVideo's `streamerURL` parameter lets attackers redirect token verification to their own server returning `{"error": fa... https://zerodaysignal.com/vulnerability/CVE-2026-33716 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces CVE‑2026‑33716, a new unauthenticated redirect vulnerability in AVideo via the `streamerURL` parameter, without indicating a PoC, exploit code, or active exploitation.

    0000049
    164 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-33716: CRITICAL] Open source video platform WWBN AVideo has a cyber security vulnerability in versions up to 26.0. An attacker can bypass authentication to control live streams. Update to commit 38...#cve,CVE-2026-33716,#cybersecurity https://cvefind.com/CVE-2026-33716

    Post summary

    A critical authentication bypass in WWBN AVideo (v≤26.0) enables control of live streams; the advisory recommends updating to commit 38 to remediate.

    0000047
    606 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-33716 - Critical WWBN AVideo is an open source video platform. In versions up to and including 26.0, the standalone live stream control endpoint at `plugin/Live/standAloneFiles/control.json.php` accepts a... https://www.thehackerwire.com/vulnerability/CVE-2026-33716/ https://t.co/kFHdv2QnXn

    Post summary

    The post announces CVE-2026-33716 as a critical flaw affecting WWBN AVideo's live stream control endpoint, but it does not provide proof-of-concept code, exploit details, active exploitation evidence, or a patch.

    0000048
    145 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appwwbnavideo---

Explore more