CVE-2026-86727
Deferred Deferred - Pending Action

AVideo Information Disclosure via Unauthenticated stats.json.php Access

Vulnerability report for CVE-2026-86727, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-10

Assigner: VulnCheck

Description

AVideo through 29.0 contains an information disclosure vulnerability in plugin/Live/stats.json.php that allows unauthenticated attackers to retrieve stream keys and m3u8 URLs by accessing the endpoint without authentication. Attackers can enumerate private, unlisted, and group-restricted live streams by parsing the hidden_applications array in the JSON response to obtain sensitive streaming credentials.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-10
Generated
2026-09-29
AI Q&A
2026-09-09
EPSS Evaluated
2026-09-27
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
avideo avideo to 29.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

AVideo through version 29.0 has an information disclosure vulnerability in the plugin/Live/stats.json.php file. This flaw allows unauthenticated attackers to access stream keys and m3u8 URLs by directly querying the endpoint without any authentication. Attackers can exploit this to enumerate private, unlisted, or group-restricted live streams by parsing the hidden_applications array in the JSON response, which contains sensitive streaming credentials.

Detection Guidance

Check if the stats.json.php endpoint is accessible without authentication by using curl commands like 'curl -I http://yourserver/plugin/Live/stats.json.php' or 'curl http://yourserver/plugin/Live/stats.json.php'. If it returns stream keys or m3u8 URLs without requiring login, the system is vulnerable.

Impact Analysis

This vulnerability can lead to unauthorized access to live streams, exposing sensitive streaming credentials. Attackers could intercept or manipulate streams, gain access to private content, or use the exposed m3u8 URLs to download or redistribute streams without permission. It poses risks to privacy, intellectual property, and potential misuse of streaming infrastructure.

Compliance Impact

This vulnerability may violate data protection regulations like GDPR and HIPAA by exposing sensitive streaming data and credentials. GDPR requires protecting personal data, while HIPAA mandates safeguarding health information. Unauthorized access to streams could lead to breaches, resulting in legal penalties, reputational damage, and loss of user trust.

Mitigation Strategies

Immediately restrict access to the stats.json.php endpoint by implementing authentication or IP whitelisting. Update AVideo to the latest version if a patch is available. Monitor network traffic for unauthorized access attempts to this endpoint.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-86727. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart