CVE-2026-33716 is a critical authentication bypass vulnerability (CVSS 9.4) affecting WWBN AVideo versions up to 26.0. An unauthenticated attacker can exploit a flaw in the live stream control endpoint to redirect token verification requests, completely bypassing authentication. This grants full unauthenticated control over any live stream, allowing actions such as dropping active publishers or managing recordings, with high impact on integrity and availability. The vulnerability has a low attack complexity and requires no user interaction. While there is no public exploit code or evidence of active exploitation, the vulnerability has garnered some community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 26.0CPE matchmatch criteria | cpe:2.3:a:wwbn:avideo:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.