CVE-2016-20035: Wowza Streaming Engine
Medium severity, CVSS 4.3. EPSS: 0.2% chance of exploitation in the next 30 days.
Wowza Streaming Engine 4.5.0 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions by crafting malicious web pages. Attackers can trick logged-in administrators into visiting a malicious site that submits POST requests to the user edit endpoint to create new admin accounts with arbitrary credentials.
Affected products
- Wowza Streaming Engine: version 4.5.0 only
Published 2026-03-16. Last modified 2026-06-17.