CVE-2026-86718 Details
Description
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vulnerability in deleteHistory.json.php and finishAll.json.php that allows unauthenticated attackers to mutate live history by making GET requests without CSRF token validation. Attackers can craft malicious pages that trigger administrator browsers to delete all live transmission history or mark streams as finished when an admin visits the attacker-controlled site.
A cross-site request forgery (CSRF) vulnerability has been identified in WWBN AVideo versions through commit c3edcc274c389816d434acadac07ee78eaf330c1. The issue resides in the 'deleteHistory.json.php' and 'finishAll.json.php' files, where unauthenticated attackers can manipulate live transmission history. This is achieved by sending GET requests that bypass CSRF token validation. Attackers can create malicious pages that, when visited by an administrator, trigger the deletion of all live transmission history or mark streams as finished.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 8, 2026CISA-ADP
Assessed Sep 8, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/WWBN/AVideo/security/advisories/GHSA-gmx5-mhqr-h7rj | CISA-ADP | AdvisoryExploitTechnical DescriptionVendor |
| https://github.com/WWBN/AVideo/security/advisories/GHSA-gmx5-mhqr-h7rj | [email protected] | AdvisoryExploitTechnical DescriptionVendor |
| https://www.vulncheck.com/advisories/wwbn-avideo-cross-site-request-forgery-via-deletehistory-json-php | [email protected] | Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-352 | Cross-Site Request Forgery (CSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| WWBN AVideo | <= c3edcc274c389816d434acadac07ee78eaf330c1 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 8, 2026 | New CVE Received | [email protected] |
| Sep 8, 2026 | CVE Modified | CISA-ADP |
Volerion