HIGH 8.7 NVD
CVE-2026-86728
AVideo through 29.0 contains an authentication bypass vulnerability in plugin/PlayLists/epg.json.php that exposes live-stream keys and private EPG schedules to
AVideo through 29.0 contains an authentication bypass vulnerability in plugin/PlayLists/epg.json.php that exposes live-stream keys and private EPG schedules to unauthenticated users. Attackers can request the endpoint with sequential user or playlist IDs to retrieve sensitive credentials, server identifiers, and complete programme schedules without authentication.
References
- https://github.com/WWBN/AVideo/security/advisories/GHSA-xpr5-7246-qvh5
- https://www.vulncheck.com/advisories/avideo-through-29.0-unauthenticated-disclosure-via-ep
- https://github.com/WWBN/AVideo/security/advisories/GHSA-xpr5-7246-qvh5
This high severity vulnerability with a CVSS score of 8.7 was published on 2026-09-08 via NVD.
vulnfeed aggregates 13138 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.