Junglewise Threat Intelligence

CVE-2026-82645: AVideo stream credentials disclosure via forgeable token

CVE-2026-82645 · Severity: high · CVSS 8.6 · Published 2026-08-30

Technologies: WWBN AVideo. Vendors: WWBN.

Executive brief

AVideo is a video streaming platform that allows users to restream content to external platforms like YouTube, Facebook, and Twitch. An unauthenticated attacker can forge authentication tokens to bypass security checks and obtain any user's streaming credentials, enabling the attacker to broadcast fraudulently to those external accounts. No user action or system compromise is required.

Technical details

The getLiveKey.json.php endpoint returns stream credentials (stream_key and stream_url) for restream destinations. A token parameter bypasses both the Live::canRestream() access control gate and the ownership check. The token is generated via AES-256-CBC encryption of an integer ID with a deterministic IV and no authentication tag. Due to CBC mode properties and the use of intval() which accepts any string beginning with a digit, an unauthenticated attacker can forge valid tokens by manipulating plaintext blocks obtained from the public url2Embed.json.php encryption oracle. An attacker can target and obtain any restream's credentials in approximately 224–269 requests without any authentication or knowledge of the site's salt. No patched versions have been released as of the advisory date.

Affected products

  • WWBN AVideo current commit e01e41ecc and earlier

Timeline

  • 2026-08-14: disclosed
  • 2026-08-30: advisory

References

Related threats