Skip to main content
HIGH

CVE-2026-86718

WWBN AVideo Cross-Site Request Forgery via deleteHistory.json.php

CVSS v3

7.1

HIGH

EPSS Score

0.2 %

exploit probability, as of 2026-09-28

CISA KEV

No

known exploited

Exploitation

poc

SSVC status

Description

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vulnerability in deleteHistory.json.php and finishAll.json.php that allows unauthenticated attackers to mutate live history by making GET requests without CSRF token validation. Attackers can craft malicious pages that trigger administrator browsers to delete all live transmission history or mark streams as finished when an admin visits the attacker-controlled site.

Technical details

Published
2026-09-08
Last Modified
2026-09-08

Frequently asked questions

What is CVE-2026-86718?

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vulnerability in deleteHistory.json.php and finishAll.json.php that allows unauthenticated attackers to mutate live history by making GET requests without CSRF token validation. Attackers can craft malicious pages that trigger administrator browsers to delete all live transmission history or mark streams as finished when an admin visits the attacker-controlled site.

Is CVE-2026-86718 actively exploited?

A proof-of-concept exploit exists for CVE-2026-86718, but active exploitation has not been confirmed at this time.

What is the CVSS score for CVE-2026-86718?

CVE-2026-86718 has a CVSS v3 base score of 7.1 (HIGH severity).

Is CVE-2026-86718 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key