Security Vulnerability in FIFA’s Systems Allows Unauthorized Access to Live Streaming Data
The article details a critical security vulnerability in FIFA’s internal systems, where a simple ID verification process granted unauthorized access to sensitive platforms. The author registered as a football agent on FIFA’s public portal, which linked their account to Microsoft Entra tenant. This access allowed them to bypass client-side role checks and reach the Streaming Management Panel, which controls live FIFA World Cup 2026 matches. The platform provided RTMP ingest URLs, stream keys, and full control over camera feeds, enabling potential hijacking of live broadcasts. The author confirmed the vulnerability by accessing real-time data, match dashboards, and internal files, highlighting risks like replacing camera feeds or altering match statistics. Despite attempts to report the issue via email, phone, and contacting agencies like CISA and the FBI, FIFA did not respond. The core flaw was client-side authorization without server-side enforcement, exposing multiple platforms. The author emphasizes the need for a formal security policy and bug bounty program, as the lack of response from FIFA underscores systemic neglect of cybersecurity.
