CVE-2026-41470
Description
A flaw was found in LIVE555. This authorization bypass vulnerability in the Real-Time Streaming Protocol (RTSP) session command handling allows a remote attacker to replay valid session tokens from unauthenticated connections. An attacker who obtains a valid session token can issue commands without authentication, leading to server crashes or the disruption of active streaming sessions, resulting in a Denial of Service (DoS).
Statement
Red Hat Product Security has determined that this vulnerability does not affect any currently supported Red Hat product. This assessment may evolve based on further analysis and discovery. For more information about this vulnerability and the products it affects, please see the linked references.
Understanding the Weakness (CWE)
Access Control
Technical Impact: Gain Privileges or Assume Identity
Messages sent with a capture-relay attack allow access to resources which are not otherwise accessible without proper authentication.
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.