CVE-2026-91965: Wwbn Avideo
High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.
WWBN AVideo through 29.0 fails to enforce user-group restrictions in the plugin/Live/stats.json.php and plugin/Live/calendar.json.php endpoints. Unauthenticated attackers can retrieve restricted live transmission details including stream keys, titles, descriptions, owner information, and direct HLS playback URLs by accessing these endpoints.
Affected products
- Wwbn Avideo: up to and including 29.0
Published 2026-09-15. Last modified 2026-09-16.