HIGH 8.7 NVD
CVE-2026-86727
AVideo through 29.0 contains an information disclosure vulnerability in plugin/Live/stats.json.php that allows unauthenticated attackers to retrieve stream keys
AVideo through 29.0 contains an information disclosure vulnerability in plugin/Live/stats.json.php that allows unauthenticated attackers to retrieve stream keys and m3u8 URLs by accessing the endpoint without authentication. Attackers can enumerate private, unlisted, and group-restricted live streams by parsing the hidden_applications array in the JSON response to obtain sensitive streaming credentials.
References
- https://github.com/WWBN/AVideo/security/advisories/GHSA-8g4j-g3r6-73xr
- https://www.vulncheck.com/advisories/avideo-through-29.0-information-disclosure-via-stats-
- https://github.com/WWBN/AVideo/security/advisories/GHSA-8g4j-g3r6-73xr
This high severity vulnerability with a CVSS score of 8.7 was published on 2026-09-08 via NVD.
vulnfeed aggregates 13138 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.