Wowza Streaming Engine 4.5.0 contains a privilege escalation vulnerability that allows authenticated read-only users to elevate privileges to administrator by manipulating POST parameters. Attackers can send POST requests to the user edit endpoint with accessLevel set to 'admin' and advUser parameters set to 'true' and 'on' to gain administrative access.
Metrics
Affected Vendors & Products
References
History
Mon, 16 Mar 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 15 Mar 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Wowza Streaming Engine 4.5.0 contains a privilege escalation vulnerability that allows authenticated read-only users to elevate privileges to administrator by manipulating POST parameters. Attackers can send POST requests to the user edit endpoint with accessLevel set to 'admin' and advUser parameters set to 'true' and 'on' to gain administrative access. | |
| Title | Wowza Streaming Engine 4.5.0 Privilege Escalation via user edit | |
| First Time appeared |
Wowza
Wowza streaming Engine |
|
| Weaknesses | CWE-352 | |
| CPEs | cpe:2.3:a:wowza:streaming_engine:4.5.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Wowza
Wowza streaming Engine |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-03-16T14:30:30.300Z
Reserved: 2026-03-15T18:22:05.054Z
Link: CVE-2016-20034
Updated: 2026-03-16T14:21:03.969Z
Status : Awaiting Analysis
Published: 2026-03-16T14:17:50.507
Modified: 2026-03-16T14:53:46.157
Link: CVE-2016-20034
No data.