Executive brief
streama is a self-hosted media streaming server that allows users to watch and track their viewing progress. An authenticated attacker can access, modify, or delete other users' viewing history and watch progress data by guessing or enumerating user IDs, effectively spying on what others are watching and manipulating their personal dashboards.
Technical details
The vulnerability is an insecure direct object reference (IDOR) in the ViewingStatusController that fails to validate ownership before allowing read and delete operations on viewing status records. An authenticated attacker can supply arbitrary primary keys to retrieve or remove other users' viewing history records without authorization. The attack requires valid authentication but no additional privileges, and is exploitable over the network. A patch was merged in commit 1fa7953 that adds ownership verification to the affected endpoints.
Affected products
- streama <UNKNOWN>
Timeline
- 2026-08-13: disclosed
- patched: Fix merged in commit 1fa7953