What is CVE-2026-68004?
CVE-2026-68004 is a critical vulnerability in OSSRS SRS (Simple Realtime Server) versions prior to 5.0.213 that allows a remote attacker to execute arbitrary code via the RTMP publish authorization mechanism. The flaw exists in vhost-level security configuration (security.enabled) and the SrsSecurity::check() function within trunk/src/app/srs_app_security.cpp, affecting the SRS RTMP listener. Immediate update to the latest version is strongly recommended for all affected instances.
Azərbaycanca: CVE-2026-68004, OSSRS SRS (Simple Realtime Server) proqramının 5.0.213 versiyasından əvvəlki versiyalarında aşkarlanmış kritik zəiflikdir. Uzaqdan hücum edən şəxs, RTMP yayım avtorizasiyası zamanı vhost səviyyəli təhlükəsizlik konfiqurasiyasındakı boşluqdan istifadə edərək ixtiyari kod icra edə bilər. Təsirə məruz qalan sistemlərdə dərhal SRS proqramını ən son versiyaya yeniləmək tövsiyə olunur.
FAQ2
What software is affected by CVE-2026-68004?
CVE-2026-68004 affects OSSRS SRS (Simple Realtime Server) versions prior to 5.0.213.
What can an attacker achieve by exploiting CVE-2026-68004?
A remote attacker can execute arbitrary code by exploiting a flaw in the vhost-level security configuration during RTMP publish authorization.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.