CVE-2026-86728
Deferred Deferred - Pending Action

Authentication Bypass in AVideo Exposes EPG Credentials

Vulnerability report for CVE-2026-86728, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-08

Assigner: VulnCheck

Description

AVideo through 29.0 contains an authentication bypass vulnerability in plugin/PlayLists/epg.json.php that exposes live-stream keys and private EPG schedules to unauthenticated users. Attackers can request the endpoint with sequential user or playlist IDs to retrieve sensitive credentials, server identifiers, and complete programme schedules without authentication.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-08
Generated
2026-09-29
AI Q&A
2026-09-09
EPSS Evaluated
2026-09-27
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
avideo avideo 29.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

AVideo through version 29.0 has an authentication bypass flaw in the plugin/PlayLists/epg.json.php file. This allows unauthenticated users to access live-stream keys and private EPG schedules by requesting the endpoint with sequential user or playlist IDs. Attackers can retrieve sensitive credentials, server identifiers, and full programme schedules without any authentication.

Detection Guidance

Check if unauthenticated requests to plugin/PlayLists/epg.json.php return sensitive data like live-stream keys or EPG schedules. Use curl to test endpoints with sequential IDs: curl -v http://[target]/plugin/PlayLists/epg.json.php?playlistId=1, curl -v http://[target]/plugin/PlayLists/epg.json.php?userId=1. Monitor logs for repeated access attempts to this endpoint.

Impact Analysis

This vulnerability allows attackers to gain unauthorized access to live-stream keys and private EPG schedules. This could lead to unauthorized viewing of streams, exposure of sensitive data, and potential disruption of services. Attackers might also use the retrieved information for further attacks or data exfiltration.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR and HIPAA due to unauthorized access to sensitive data. GDPR requires protection of personal data, while HIPAA mandates safeguards for protected health information. A breach could result in legal penalties, fines, and reputational damage.

Mitigation Strategies

Immediately update AVideo to the latest version (29.0 or higher) to patch the authentication bypass. If an update is unavailable, restrict access to plugin/PlayLists/epg.json.php via web server rules (e.g., Apache .htaccess or Nginx deny rules). Implement authentication for all API endpoints and disable directory listing to prevent enumeration of IDs.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-86728. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart