CVE-2026-41470
LIVE555 < 2026.04.22 RTSP Server Authorization Bypass via Session Token
CVSS Score
5.9
EPSS Score
0.0%
EPSS Percentile
0th
LIVE555 before 2026.04.22 contains an authorization bypass vulnerability in RTSP session command handling that allows attackers to replay valid Session tokens from unauthenticated connections. Attackers who obtain a valid Session token can issue PLAY and TEARDOWN commands from a second TCP connection without authentication, causing server crashes through virtual function call errors or disrupting active streams by terminating victim sessions.
| CWE | CWE-863 |
| Vendor | live networks, inc. |
| Product | live555 |
| Published | May 19, 2026 |
| Last Updated | May 20, 2026 |
Stay Ahead of the Next One
Get instant alerts for live networks, inc. live555
Be the first to know when new medium vulnerabilities affecting live networks, inc. live555 are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Affected Versions
Live Networks, Inc. / LIVE555
0 < 2026.04.22
References
Credits
Younghyo Cho @ CIS Lab., Seoultech VulnCheck