CVE-2016-20035: Wowza Streaming Engine

Medium severity, CVSS 4.3. EPSS: 0.2% chance of exploitation in the next 30 days.

Wowza Streaming Engine 4.5.0 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions by crafting malicious web pages. Attackers can trick logged-in administrators into visiting a malicious site that submits POST requests to the user edit endpoint to create new admin accounts with arbitrary credentials.

Affected products

  • Wowza Streaming Engine: version 4.5.0 only

Published 2026-03-16. Last modified 2026-06-17.