HarborGuard / CVE
Back to search
HIGHCVE-2026-41470Published Modified CNA VulnCheck

CVE-2026-41470: LIVE555 < 2026.04.22 RTSP Server Authorization Bypass via Session Token

LIVE555 before 2026.04.22 contains an authorization bypass vulnerability in RTSP session command handling that allows attackers to replay valid Session tokens from unauthenticated connections. Attackers who obtain a valid Session token can issue PLAY and TEARDOWN commands from a second TCP connection without authentication, causing server crashes through virtual function call errors or disrupting active streams by terminating victim sessions.

Metrics

CVSS v4.0
8.2
Severity
HIGH
Fixed in
2026.04.22
Affected Products
1

Fix available

2026.04.22
Affected packages
  • Live Networks, Inc. / LIVE555
    < 2026.04.22 (from 0)
CVSS Vector
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N