---
id: CVE-2026-86728
title: >-
  AVideo through 29.0 contains an authentication bypass vulnerability in
  plugin/PlayLists/epg.json.php that exposes live-stream keys and private EPG
  schedules to unauthenticated users
summary: >-
  AVideo through 29.0 contains an authentication bypass vulnerability in
  plugin/PlayLists/epg.json.php that exposes live-stream keys and private EPG
  schedules to unauthenticated users. Attackers can request the endpoint with
  sequential use…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-306
vendor: WWBN
product: AVideo
affected:
  - AVideo <= 29.0
published: '2026-09-08'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T19:53:13.400'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-86728'
references:
  - url: 'https://github.com/WWBN/AVideo/security/advisories/GHSA-xpr5-7246-qvh5'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/avideo-through-29.0-unauthenticated-disclosure-via-epg-json-php
    label: disclosure@vulncheck.com
  - url: 'https://github.com/WWBN/AVideo/security/advisories/GHSA-xpr5-7246-qvh5'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-08T15:32:19.057471Z'
ingestedAt: '2026-09-08T15:33:26.987Z'
epss: 0.00552
epssPercentile: 0.4369
---

## Overview

AVideo through 29.0 contains an authentication bypass vulnerability in plugin/PlayLists/epg.json.php that exposes live-stream keys and private EPG schedules to unauthenticated users. Attackers can request the endpoint with sequential user or playlist IDs to retrieve sensitive credentials, server identifiers, and complete programme schedules without authentication.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
