CVE-2024-52052: Wowza Streaming Engine

High severity, CVSS 7.2. EPSS: 0.5% chance of exploitation in the next 30 days.

Wowza Streaming Engine below 4.9.1 permits an authenticated Streaming Engine Manager administrator to define a custom application property and poison a stream target for high-privilege remote code execution.

Affected products

  • Wowza Streaming Engine: from 4.3.0, before 4.9.1 (fixed in 4.9.1)

Published 2024-11-21. Last modified 2026-06-17.