Junglewise Threat Intelligence

CVE-2026-90543: WWBN AVideo missing authentication in socketMessageLiveOwner.json.php

CVE-2026-90543 · Severity: medium · CVSS 5.3 · Published 2026-09-12

Technologies: WWBN AVideo. Vendors: WWBN.

Executive brief

WWBN AVideo is a video hosting and streaming platform. When the Live plugin is enabled, a flaw in the notification system allows an unauthenticated attacker who knows an administrator's live stream key to send arbitrary in-app notification messages to that administrator. This could be used for social engineering, malicious notifications, or service disruption.

Technical details

The vulnerability is a missing authentication and authorization check (CWE-306, CWE-862) in plugin/Live/socketMessageLiveOwner.json.php. The script accepts `key` and `msg` parameters from $_REQUEST and resolves the stream owner via LiveTransmition::keyExists, then verifies the stream owner (not the caller) is an administrator. However, it performs no User::isLogged() check and enforces no CSRF token, allowing unauthenticated remote attackers to call sendSocketSuccessMessageToUsers_id. An attacker who knows a valid administrator live stream key can deliver arbitrary socket notification messages to that administrator. The vulnerability requires only network access and knowledge of a valid stream key; no user interaction or privileges are required. At the time of publication, this issue was unpatched.

Affected products

  • WWBN AVideo commit c3edcc274c389816d434acadac07ee78eaf330c1 and earlier (with Live plugin enabled)

Timeline

  • 2026-09-12: disclosed
  • other: unpatched at time of publication

References

Related threats