Wowza Streaming Engine 4.5.0 contains a privilege escalation vulnerability that allows authenticated read-only users to elevate privileges to administrator by manipulating POST parameters. Attackers can send POST requests to the user edit endpoint with accessLevel set to 'admin' and advUser parameters set to 'true' and 'on' to gain administrative access.
References
| Link | Resource |
|---|---|
| http://www.zeroscience.mk/en/vulnerabilities/ZSL-2016-5340.php | Exploit Third Party Advisory |
| https://www.exploit-db.com/exploits/40133 | Exploit Third Party Advisory VDB Entry |
| https://www.vulncheck.com/advisories/wowza-streaming-engine-privilege-escalation-via-user-edit | Third Party Advisory |
Configurations
History
No history.
Information
Published : 2026-03-16 14:17
Updated : 2026-03-19 14:16
NVD link : CVE-2016-20034
Mitre link : CVE-2016-20034
CVE.ORG link : CVE-2016-20034
JSON object : View
Products Affected
wowza
- streaming_engine
CWE
CWE-352
Cross-Site Request Forgery (CSRF)
