Security researcher bobdahacker discovered a critical vulnerability in FIFA’s digital infrastructure that could have allowed unauthorized individuals to hijack live match broadcasts and manipulate sensitive tournament data.
Key Points
- The researcher gained access to the FIFA Football Data Platform by exploiting a misconfigured Microsoft Entra account system.
- The flaw allowed potential control over RTMP ingest URLs, which serve as the primary broadcast feed for live World Cup matches.
- Exposed systems included administrative dashboards, player bios, match scores, and the FIFA AI Pro analysis tool.
- The researcher bypassed client-side access restrictions that failed to verify user roles on the server side.
- Instead of exploiting the access, the researcher reported the security gaps to FIFA, their streaming contractors, and law enforcement.