
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-34245 is a missing authorization vulnerability in WWBN AVideo, an open source video platform, that allows any authenticated user with streaming permission to create or modify broadcast schedules targeting any playlist on the platform, regardless of ownership. Affected versions include all releases up to and including 26.0. The vulnerability was published on March 27, 2026, with a patch available in commit 1e6dc20172de986f60641eb4fdb4090f079ffdce. It carries a CVSS v3.1 base score of 6.3 (Medium) (Github Advisory, Feedly).
The root cause is CWE-862 (Missing Authorization): the plugin/PlayLists/View/Playlists_schedules/add.json.php endpoint performs only a capability check (User::canStream()) but never verifies that the requesting user owns the target playlist. The attacker-controlled playlists_id POST parameter is passed directly to Playlists_schedules::setPlaylists_id() without any ownership validation, and the save() method only checks that playlists_id is non-empty. When the scheduled broadcast executes via plugin/PlayLists/run.php, it calls Rebroadcaster::rebroadcastVideo() using the victim playlist owner's user ID ($pl->getUsers_id()), not the schedule creator's. By contrast, all other playlist modification endpoints in AVideo (e.g., saveShowOnTV.json.php, playListToSerie.php) correctly invoke PlayLists::canManagePlaylist() for ownership verification (Github Advisory).
Successful exploitation enables content hijacking, allowing an attacker to force-broadcast content from any user's playlist — including private or paid content — under the victim's identity, making it appear the victim initiated the broadcast. Attackers can also disrupt a victim's ongoing live streams, tamper with or redirect existing broadcast schedules, and consume the victim's server bandwidth allocation. The integrity and availability of affected users' streaming services are directly impacted, and limited confidentiality exposure arises from unauthorized access to private playlist content (Github Advisory).
A proof-of-concept exploit is publicly available in the GitHub Security Advisory, consisting of concrete curl commands that demonstrate the authorization bypass against a live AVideo deployment. Exploitation requires only a valid authenticated session with streaming permission — no administrative privileges are needed. The EPSS score is approximately 0.018% (0.034% per Feedly), indicating low current exploitation probability. There is no evidence of in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog (Github Advisory).
PHPSESSID session cookie.playlists_id:curl -X POST 'https://target.com/plugin/PlayLists/View/Playlists_schedules/add.json.php' \
-H 'Cookie: PHPSESSID=<your_session_id>' \
-d 'playlists_id=<VICTIM_PLAYLIST_ID>&name=hijacked&start_datetime=2026-03-26+12:00:00&finish_datetime=2026-03-27+12:00:00&loop=1&repeat=d¶meters={}'{"error":false} confirms the schedule was created for the victim's playlist without ownership verification.id in the POST body to redirect or tamper with it:curl -X POST 'https://target.com/plugin/PlayLists/View/Playlists_schedules/add.json.php' \
-H 'Cookie: PHPSESSID=<your_session_id>' \
-d 'id=<SCHEDULE_ID>&playlists_id=<VICTIM_PLAYLIST_ID>&name=modified&start_datetime=2026-03-26+00:00:00&finish_datetime=2026-03-28+00:00:00&loop=1&repeat=d¶meters={}'plugin/PlayLists/run.php triggers the rebroadcast under the victim playlist owner's user identity, completing the hijack (Github Advisory)./plugin/PlayLists/View/Playlists_schedules/add.json.php from users who do not own the playlists_id specified in the request body; unusual rebroadcast activity originating from the server at scheduled times not initiated by the playlist owner.add.json.php with playlists_id values belonging to other users; run.php execution logs showing rebroadcasts attributed to a user ID that did not create the schedule.Apply the patch introduced in commit 1e6dc20172de986f60641eb4fdb4090f079ffdce, which adds PlayLists::canManagePlaylist() ownership checks to add.json.php for both new schedule creation and modification of existing schedules. As an interim workaround, restrict streaming permissions to only fully trusted users until the patch can be applied. Additionally, monitor broadcast schedules for unauthorized modifications or unusual rebroadcast activity as a detection measure (Github Advisory, Patch Commit).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."