#VU125498 Missing Authentication for Critical Function in AVideo - CVE-2026-34731
Published: April 8, 2026
AVideo
World Wide Broadcast Network
Description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to missing authentication for critical function in the on_publish_done.php endpoint in the Live plugin when handling RTMP callback requests. A remote attacker can send a crafted POST request with a stream key to cause a denial of service.
Active stream keys can be enumerated through the unauthenticated stats.json.php endpoint.