Executive brief
WWBN AVideo is an open-source platform used for hosting and streaming video content. A security flaw in the platform's Live plugin allows unauthorized individuals to abruptly terminate any active live broadcast without needing a password or account. This can lead to significant service disruptions, loss of viewer engagement, and reputational damage for broadcasters using the platform.
Technical details
A missing authentication vulnerability (CWE-306) exists in the AVideo Live plugin's RTMP callback handler. The 'on_publish_done.php' endpoint, intended for internal use by the RTMP server (e.g., Nginx-RTMP), fails to verify the source of incoming requests or validate user sessions. An attacker can first harvest active stream keys from the unauthenticated 'stats.json.php' endpoint and then send a crafted POST request containing a stream key to 'on_publish_done.php'. This triggers the 'finishFromTransmitionHistoryId' method, marking the stream as finished in the database and effectively disconnecting the live broadcast. As of the advisory date, no official patch is available, though restricting the endpoint to localhost is the recommended mitigation.
Affected products
- WWBN AVideo <= 26.0
Timeline
- 2026-03-30: advisory: GitHub Security Advisory published
- 2026-03-31: disclosed: CVE-2026-34731 published to NVD