VYPR
Critical severity10.0NVD Advisory· Published Mar 23, 2026· Updated Jun 17, 2026

CVE-2026-33478

CVE-2026-33478

Description

WWBN AVideo is an open source video platform. In versions up to and including 26.0, multiple vulnerabilities in AVideo's CloneSite plugin chain together to allow a completely unauthenticated attacker to achieve remote code execution. The clones.json.php endpoint exposes clone secret keys without authentication, which can be used to trigger a full database dump via cloneServer.json.php. The dump contains admin password hashes stored as MD5, which are trivially crackable. With admin access, the attacker exploits an OS command injection in the rsync command construction in cloneClient.json.php to execute arbitrary system commands. Commit c85d076375fab095a14170df7ddb27058134d38c contains a patch.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
wwbn/avideoPackagist
<= 26.0

Affected products

3
  • WWBN/Avideo2 versions
    cpe:2.3:a:wwbn:avideo:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:wwbn:avideo:*:*:*:*:*:*:*:*range: <=26.0
    • (no CPE)range: <= 26.0
  • ghsa-coords
    Range: <= 26.0

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.