---
id: CVE-2026-86726
title: >-
  AVideo through 29.0 contains an information disclosure vulnerability in
  restreamsActive.json.php that allows authenticated streamers to enumerate
  source stream keys and identities of all other streamers' active restreams
summary: >-
  AVideo through 29.0 contains an information disclosure vulnerability in
  restreamsActive.json.php that allows authenticated streamers to enumerate
  source stream keys and identities of all other streamers' active restreams.
  The endpoint fa…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-522
vendor: WWBN
product: AVideo
affected:
  - AVideo <= 29.0
published: '2026-09-08'
updated: '2026-09-19'
sourceUpdated: '2026-09-19T15:17:06.767'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-86726'
references:
  - url: 'https://github.com/WWBN/AVideo/security/advisories/GHSA-qh45-c3p8-jh4g'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/avideo-through-29.0-information-disclosure-via-restreamsactive-json-php
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
epss: 0.0036
epssPercentile: 0.27101
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-18T17:42:34.010441Z'
ingestedAt: '2026-09-08T15:33:26.987Z'
---

## Overview

AVideo through 29.0 contains an information disclosure vulnerability in restreamsActive.json.php that allows authenticated streamers to enumerate source stream keys and identities of all other streamers' active restreams. The endpoint fails to filter results by user ownership, exposing sensitive transmission credentials and streamer identity across all accounts to any user with streaming capability.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
