Summary
CVE-2026-84187 is a missing-authentication vulnerability (CWE-284) in the AVideo platform’s RTMP callback handler, plugin/Live/on_publish.php. Unauthenticated attackers can send crafted POST requests to this endpoint to mark arbitrary scheduled live broadcasts as failed, silently disrupting streaming operations. The issue affects AVideo version 29.0 and earlier and carries a High severity rating.
Technical details
- Root cause:
on_publish.phpis missing theLive::assertRtmpCallbackAllowed()check that is present in sibling RTMP callback files (on_publish_done.php,on_record_done.php), so the endpoint never verifies that the request actually originates from the trusted RTMP server. - Trigger conditions: An attacker sends a POST request with a
nameparameter containing a fabricated stream key matching the pattern-ps-<N>, whereNis a schedule identifier. The code extracts the schedule ID without verifying the key belongs to that schedule or that the caller is authorized. - Attack vector: Network-based, no authentication or user interaction required, low attack complexity.
- Impact: The request reaches
on_publish_denied(), which updates the corresponding scheduled broadcast’s status to "failed," allowing any internet-facing attacker to cancel or disrupt arbitrary scheduled live broadcasts by iterating schedule IDs. All requests return identical responses, leaving no distinguishing attack signature.
Affected software
- WWBN AVideo: all versions up to and including 29.0
Severity
CVSS v3.1 Base Score: 8.2 (High)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
(Note: AVideo’s own advisory and CVE record also list a CVSS v3.1/High rating in the 8.2–8.8 range depending on scoring standard used.)
Mitigation and recommended actions
- Immediate: No patched AVideo release has been published at the time of advisory disclosure. Monitor the vendor’s GitHub security advisory (GHSA-v395-2xmq-cg23) for a fix that adds the missing
Live::assertRtmpCallbackAllowed()check toon_publish.php, and upgrade as soon as it is released. - If no patch is available:
- Restrict network access to the RTMP callback endpoints (
plugin/Live/on_publish.phpand related files) so they are reachable only from the trusted RTMP/media server, not the public internet. - Deploy a web application firewall (WAF) rule to block external POST requests to
on_publish.phpthat are not sourced from the internal streaming server’s IP. - Monitor scheduled broadcast status changes for unexpected transitions to "failed" as a sign of exploitation attempts.
- Restrict network access to the RTMP callback endpoints (
How IONIX identifies potentially affected assets
IONIX matches the following signals against data already collected when it crawled the asset; identifying the technology sends no request beyond that crawl.
- Page title:
Sign In - AVideo,AVideo - Raw response body:
id="avideoModal",avideoAlert(,avideoModalIframe(

