CVE-2026-41470
Awaiting Analysis
Awaiting Analysis - Queue
Authorization Bypass in LIVE555 RTSP Session Handling
Publication date: 2026-05-19
Last updated on: 2026-05-19
Assigner: VulnCheck
Description
Description
LIVE555 before 2026.04.22 contains an authorization bypass vulnerability in RTSP session command handling that allows attackers to replay valid Session tokens from unauthenticated connections. Attackers who obtain a valid Session token can issue PLAY and TEARDOWN commands from a second TCP connection without authentication, causing server crashes through virtual function call errors or disrupting active streams by terminating victim sessions.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| live555 | live555 | to 2026.04.22 (exc) |
| live555 | live555 | From 2025.01.17 (inc) to 2026.04.01 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-863 | The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. |