
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-34731 is a missing authentication vulnerability in WWBN AVideo's Live plugin that allows unauthenticated attackers to terminate any active live stream via a crafted HTTP POST request. It affects WWBN AVideo versions 26.0 and prior, with no patched version available at the time of initial publication (March 30, 2026). The vulnerability was discovered by aisafe.io, published to the GitHub Advisory Database on April 1, 2026, and assigned GHSA-4jcg-jxpf-5vq3. It carries a CVSS v3.1 base score of 7.5 (High) (GitHub Advisory, WWBN Advisory).
The root cause is CWE-306 (Missing Authentication for Critical Function): the plugin/Live/on_publish_done.php endpoint, intended to be called by a local RTMP server (e.g., Nginx-RTMP) upon stream completion, performs no authentication or authorization checks — no User::isLogged(), User::isAdmin(), or token validation. The endpoint accepts a POST parameter name (the stream key) and directly invokes LiveTransmitionHistory::getLatest() and LiveTransmitionHistory::finishFromTransmitionHistoryId() to mark the stream as finished in the database. Compounding the issue, stream keys can be freely enumerated from the equally unauthenticated plugin/Live/stats.json.php endpoint, which exposes active stream metadata. Because the endpoint is a standard HTTP resource rather than a localhost-only callback, any remote client can invoke it (WWBN Advisory, GitHub Advisory).
Successful exploitation results in a denial-of-service against all live streaming functionality on the affected AVideo platform. An unauthenticated remote attacker can enumerate all active stream keys and systematically terminate every live broadcast, causing complete availability loss for the live streaming service. There is no confidentiality or integrity impact — data is not exposed or modified beyond the stream session state in the database (WWBN Advisory).
A proof-of-concept exploit consisting of curl commands and an automated bash script is publicly documented in the GitHub Security Advisory, making exploitation trivial for any attacker with network access to the target (WWBN Advisory). No credentials, special tools, or complex preconditions are required. The EPSS score is approximately 0.069% (21st percentile), indicating a relatively low but non-negligible probability of exploitation in the near term (GitHub Advisory). There is no evidence of in-the-wild exploitation or threat actor attribution at this time, and the vulnerability is not listed in the CISA KEV catalog.
stats.json.php endpoint to retrieve active stream metadata, including stream keys:curl -s "https://your-avideo-instance.com/plugin/Live/stats.json.php" | python3 -m json.toolapplications[].live.streams[].name fields.on_publish_done.php with the stream key as the name parameter:curl -X POST "https://your-avideo-instance.com/plugin/Live/on_publish_done.php" -d "name=STREAM_KEY_HERE"The server responds with HTTP 200 and marks the stream as finished in the live_transmitions_history database table./plugin/Live/stats.json.php from external IP addresses (not the local RTMP server); HTTP POST requests to /plugin/Live/on_publish_done.php originating from IP addresses other than 127.0.0.1 or ::1.on_publish_done.php with varying name parameter values in rapid succession; HTTP 200 responses to these requests from non-localhost sources.live_transmitions_history table marking streams as finished at times inconsistent with actual streamer activity; multiple streams terminated within a short time window.No patched version of WWBN AVideo was available at the time of initial disclosure (versions ≤ 26.0 are affected); users should monitor the WWBN/AVideo repository for a patched release. As an immediate workaround, restrict access to plugin/Live/on_publish_done.php to localhost only by adding an IP check at the top of the file:
if (!in_array($_SERVER['REMOTE_ADDR'], ['127.0.0.1', '::1'])) {
http_response_code(403);
die('Forbidden');
}Additionally, implement web server-level (e.g., Nginx or Apache) access controls to block external requests to both on_publish_done.php and stats.json.php, and apply network firewall rules to limit access to these endpoints to trusted RTMP server IPs only (WWBN Advisory, GitHub Advisory).
The vulnerability was noted on Mastodon by TheHackerWire and received brief coverage on CVE aggregator platforms such as cvefeed.io and radar.offseq.com shortly after disclosure. Community discussion has been limited, consistent with the moderate severity and niche affected software. The advisory credits aisafe.io as the finder and adrgs as the reporter (WWBN Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."