CVE-2026-41470

LIVE555 before 2026.04.22 contains an authorization bypass vulnerability in RTSP session command handling that allows attackers to replay valid Session tokens from unauthenticated connections. Attackers who obtain a valid Session token can issue PLAY and TEARDOWN commands from a second TCP connection without authentication, causing server crashes through virtual function call errors or disrupting active streams by terminating victim sessions.
Configurations

No configuration.

History

19 May 2026, 19:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-19 19:16

Updated : 2026-05-19 21:08


NVD link : CVE-2026-41470

Mitre link : CVE-2026-41470

CVE.ORG link : CVE-2026-41470


JSON object : View

Products Affected

No product.

CWE
CWE-863

Incorrect Authorization