Sploitus

CVE-2026-41470

No indexed exploits for CVE-2026-41470 yet

LIVE555 before 2026.04.22 contains an authorization bypass vulnerability in RTSP session command handling that allows attackers to replay valid Session tokens from unauthenticated connections. Attackers who obtain a valid Session token can issue PLAY and TEARDOWN commands from a second TCP connection without authentication, causing server crashes through virtual function call errors or disrupting active streams by terminating victim sessions.

Affected products
Live555
Fix
Available
CVSS 4.0
8.2 HIGH
CVSS 3.1
5.9 MEDIUM
EPSS
0.5% (39th percentile)
Weakness
CWE-863
NVD status
Awaiting Analysis
Published
2026-05-19
CVE-2026-41470 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-41470 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-41470 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.