CVE-2026-86718
Deferred Deferred - Pending Action

CSRF in AVideo Allows History Manipulation

Vulnerability report for CVE-2026-86718, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-08

Assigner: VulnCheck

Description

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vulnerability in deleteHistory.json.php and finishAll.json.php that allows unauthenticated attackers to mutate live history by making GET requests without CSRF token validation. Attackers can craft malicious pages that trigger administrator browsers to delete all live transmission history or mark streams as finished when an admin visits the attacker-controlled site.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-08
Generated
2026-09-29
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wwbn avideo *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-352 The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a cross-site request forgery (CSRF) flaw in WWBN AVideo. It allows unauthenticated attackers to manipulate live history by sending GET requests to deleteHistory.json.php and finishAll.json.php without requiring CSRF token validation. Attackers can trick administrators into deleting all live transmission history or marking streams as finished by having them visit a malicious site.

Detection Guidance

Detecting this vulnerability requires checking for unauthorized modifications to live history or stream status in WWBN AVideo. Monitor server logs for unusual GET requests to deleteHistory.json.php or finishAll.json.php without valid CSRF tokens. Inspect network traffic for admin sessions making unexpected changes to history or stream states.

Impact Analysis

If you are an administrator or user with access to AVideo's live history, attackers could exploit this to delete your transmission history or falsely mark streams as finished. This could disrupt live broadcasts, remove important records, or cause confusion about stream status without requiring direct access to your account.

Compliance Impact

This vulnerability could impact compliance by allowing unauthorized deletion or alteration of live transmission history, which may be considered sensitive data under GDPR or HIPAA. If such data is required for audits or records, its deletion could violate retention policies or data integrity requirements.

Mitigation Strategies

Immediately update WWBN AVideo to the latest commit or patch addressing this issue. Disable GET requests for deleteHistory.json.php and finishAll.json.php endpoints if possible. Implement CSRF token validation for all sensitive actions. Review server logs for signs of exploitation and remove any unauthorized changes to history or streams.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-86718. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart