THREAT OPS › Threat News › [NVD] CVE-2026-82645 (HIGH 8.6) — AVideo (current commit e01e41ecc and earlier) exposes stream credentials through the plugin/Live/view/Live_restreams/getLiveKey.json.php endpoint. Supplying a 'token' request parameter waives both the Live::canRestream() access gate and the restream ownership check, causing the e
[NVD] CVE-2026-82645 (HIGH 8.6) — AVideo (current commit e01e41ecc and earlier) exposes stream credentials through the plugin/Live/view/Live_restreams/getLiveKey.json.php endpoint. Supplying a 'token' request parameter waives both the Live::canRestream() access gate and the restream ownership check, causing the e
CVE-2026-82645 CVSS: 8.6 HIGH Published: 2026-08-30T15:16:44.863
AVideo (current commit e01e41ecc and earlier) exposes stream credentials through the plugin/Live/view/Live_restreams/getLiveKey.json.php endpoint. Supplying a 'token' request parameter waives both the Live::canRestream() access gate and the restream ownership check, causing the endpoint to return any restream's stream_key and stream
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2026-82645cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-82645