A basic security flaw allowed a security researcher to access FIFA’s internal systems and the ability to monitor World Cup television broadcasts.



  • Researcher “BobDaHacker” found a flaw in the FIFA API that allowed anyone to hijack live TV streams and commentator comments.
  • The error was due to a lack of authorization checks; FIFA patched quickly but did not give credit to the search engine
  • Experts warn that it highlights CWE-602 and the danger of confusing authentication with authorization

A bug in an internal FIFA system allowed anyone to modify what is broadcast to television broadcasters and what is broadcast to TV commentators calling the 2026 FIFA World Cup matches. Fortunately for everyone, the bug was discovered by a white hat hacker and fixed before malicious actors could exploit it.

A security researcher with the alias BobDaHacker recently reported that he could take full control over the television broadcast. They did this by registering as a player agent on FIFA’s official agent registration platform and then abusing a vulnerability in FIFA’s back-end API to access multiple internal platforms.

Leave a Comment

Your email address will not be published. Required fields are marked *