CVE-2026-33478
CRITICAL EPSS 95.9%
Published Mar 23, 20263mo ago · Modified Jun 17, 20261w ago
10.0 CVSS 3.1
Published Mar 23, 2026 3mo ago
Last Modified Jun 17, 2026 1w ago
Description
WWBN AVideo is an open source video platform. In versions up to and including 26.0, multiple vulnerabilities in AVideo's CloneSite plugin chain together to allow a completely unauthenticated attacker to achieve remote code execution. The `clones.json.php` endpoint exposes clone secret keys without authentication, which can be used to trigger a full database dump via `cloneServer.json.php`. The dump contains admin password hashes stored as MD5, which are trivially crackable. With admin access, the attacker exploits an OS command injection in the rsync command construction in `cloneClient.json.php` to execute arbitrary system commands. Commit c85d076375fab095a14170df7ddb27058134d38c contains a patch.
CVSS Details
Base Score
Exploitability
Impact
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction None
Scope Changed
Confidentiality High
Integrity High
Availability High
Threat Intelligence
EPSS Exploit Probability
95.9% percentile
Exploit & Patch Status
Public Exploit Known
Patch Available
Weaknesses 2
CWE-284
CWE-78 OS Command Injection Injection
Affected Products 1
| Vendor | Product | Version | Range |
|---|---|---|---|
| wwbn | avideo | * | ≤26.0 |
References 2
- github.com https://github.com/WWBN/AVideo/commit/c85d076375fab095a14170df7ddb27058134d38c
- github.com https://github.com/WWBN/AVideo/security/advisories/GHSA-687q-32c6-8x68
Remediation
- github.com https://github.com/WWBN/AVideo/commit/c85d076375fab095a14170df7ddb27058134d38c