CVE-2026-89252
Received Received - Intake

AVideo LiveLink Ownership Bypass Vulnerability

Vulnerability report for CVE-2026-89252, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-11

Assigner: VulnCheck

Description

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to verify ownership in addLiveLink.php when updating LiveLinks, allowing authenticated users to modify other users' links. A canStream user can overwrite another user's LiveLink HLS source and metadata by supplying an existing linkId, redirecting viewers to attacker-controlled media.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-11
Generated
2026-09-11
AI Q&A
2026-09-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
avideo avideo *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

AVideo has a vulnerability in addLiveLink.php where it fails to verify if a user owns a LiveLink before allowing updates. Authenticated users with canStream privileges can modify another user's LiveLink by providing its linkId, redirecting viewers to attacker-controlled media.

Detection Guidance

Check AVideo logs for unauthorized modifications to LiveLinks, particularly POST requests to addLiveLink.php with linkId parameters. Monitor for changes in HLS stream sources or metadata without proper ownership verification.

Impact Analysis

An attacker could replace your LiveLink with malicious content, causing visitors to your channel to view unauthorized media. This could damage your reputation or spread misinformation under your name.

Mitigation Strategies

Update AVideo to the latest commit beyond c3edcc274c389816d434acadac07ee78eaf330c1. Disable the canStream role's ability to modify LiveLinks if only admins should manage them. Review LiveLink configurations for unauthorized changes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89252. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart