AVideo contains a missing authentication vulnerability in plugin/Live/on_publish.php that allows unauthenticated attackers to mark arbitrary scheduled broadcasts as failed by sending crafted POST requests with schedule identifiers. Attackers can exploit the unguarded RTMP callback endpoint to modify scheduled broadcast status fields by supplying fabricated stream keys matching the pattern -ps-<N>, silently canceling any scheduled live broadcast without credentials or authorization.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
AVideo's Live plugin contains a critical authentication flaw in its RTMP callback handler (plugin/Live/on_publish.php) that allows unauthenticated attackers to manipulate scheduled broadcast status. By crafting POST requests with fabricated stream keys following the pattern -ps-<N>, adversaries can mark arbitrary scheduled broadcasts as failed without providing credentials or authorization. This vulnerability affects any organization deploying AVideo for live streaming operations, enabling attackers to disrupt scheduled content delivery, damage reputation, or create denial-of-service conditions against planned broadcasts—all without detection or audit trails showing unauthorized access.
While this CVE lacks direct MITRE ATT&CK mappings, Casky's extended reasoning across its 754 security skills would identify this as an Improper Authentication (CWE-284) pattern indicative of T1133 (External Remote Services) abuse and potential T1561 (Disk Wipe) attack preparation through service disruption. Practitioners would observe findings showing unauthenticated endpoint access, unauthorized state modification of critical resources, and absence of authentication checks on callback functions. Casky's skills would flag the missing authentication boundary, the predictable stream key pattern enabling brute-force manipulation, and the lack of request validation—surfacing these as high-priority detections indicating active reconnaissance or exploitation attempts against unprotected broadcast infrastructure.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-84187. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation