CVE-2026-86728 Details
Description
AVideo through 29.0 contains an authentication bypass vulnerability in plugin/PlayLists/epg.json.php that exposes live-stream keys and private EPG schedules to unauthenticated users. Attackers can request the endpoint with sequential user or playlist IDs to retrieve sensitive credentials, server identifiers, and complete programme schedules without authentication.
An authentication bypass vulnerability has been identified in AVideo versions through 29.0, specifically within the plugin/PlayLists/epg.json.php file. This vulnerability allows unauthenticated users to access live-stream keys and private Electronic Program Guide (EPG) schedules. The issue arises because the epg.json.php endpoint does not require authentication and directly reads user or playlist IDs from the request. Attackers can exploit this by sending requests with sequential IDs to retrieve sensitive information, including credentials, server identifiers, and complete program schedules, without any authentication.
No official patch is available. However, it is recommended to apply an authentication requirement for accessing the EPG JSON endpoint, or to implement the same filters used by the sibling EPG endpoints that do require authentication.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 8, 2026CISA-ADP
Assessed Sep 8, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/WWBN/AVideo/security/advisories/GHSA-xpr5-7246-qvh5 | CISA-ADP | AdvisoryExploitTechnical AnalysisVendor |
| https://github.com/WWBN/AVideo/security/advisories/GHSA-xpr5-7246-qvh5 | [email protected] | AdvisoryExploitTechnical AnalysisVendor |
| https://www.vulncheck.com/advisories/avideo-through-29.0-unauthenticated-disclosure-via-epg-json-php | [email protected] | Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-306 | Missing Authentication for Critical Function | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| WWBN AVideo | <= 29.0 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 8, 2026 | New CVE Received | [email protected] |
| Sep 8, 2026 | CVE Modified | CISA-ADP |
Volerion