{"id":"CVE-2026-68004","title":"An issue in OSSRS SRS (Simple Realtime Server) <v5.0.213 allows a remote attacker to execute arbitrary code via RTMP publish authorization, vhost-level security configuration (security.enabled), SrsSecurity::check(), trunk/src/app/srs_ap…","summary":"An issue in OSSRS SRS (Simple Realtime Server) <v5.0.213 allows a remote attacker to execute arbitrary code via RTMP publish authorization, vhost-level security configuration (security.enabled), SrsSecurity::check(), trunk/src/app/srs_ap…","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-284"],"published":"2026-08-17","updated":"2026-09-09","sourceUpdated":"2026-09-09T16:04:24.933","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-68004","references":[{"url":"https://github.com/ossrs/srs/releases/tag/v5.0-r3","label":"cve@mitre.org"},{"url":"https://github.com/xuwu-xuwu/CVE-2026-68004","label":"cve@mitre.org"},{"url":"https://github.com/xuwu-xuwu/CVE-2026-68004","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","exploit-available"],"epss":0.00717,"epssPercentile":0.52345,"exploits":{"github":1,"githubRepos":["https://github.com/xuwu-xuwu/CVE-2026-68004"],"checkedAt":"2026-09-23T07:14:37.282Z"},"exploitAvailable":true,"ingestedAt":"2026-09-09T16:14:05.513Z","slug":"CVE-2026-68004","body":"## Overview\n\nAn issue in OSSRS SRS (Simple Realtime Server) <v5.0.213 allows a remote attacker to execute arbitrary code via RTMP publish authorization, vhost-level security configuration (security.enabled), SrsSecurity::check(), trunk/src/app/srs_app_security.cpp, and SRS RTMP listener components\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"abyssal","depthScore":66,"depthScoreParts":{"impact":53.9,"likelihood":0.1,"exploitation":12,"ransomware":0},"changes":[]}