CVE-2026-27732: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-27732 is an authenticated Server-Side Request Forgery (SSRF) vulnerability in WWBN AVideo, an open source video platform. The flaw exists in the aVideoEncoder.json.php API endpoint, which accepts a downloadURL parameter and fetches the referenced resource server-side without proper validation or an allow-list. All AVideo versions prior to 22.0 are affected. The vulnerability was responsibly disclosed by researcher Arkadiusz Marta, published to the GitHub Advisory Database on February 23, 2026, and assigned a CVSS v3.1 score of 8.1 (High) and a CVSS v4.0 score of 8.6 (High) (GitHub Advisory, Github Advisory).

Technical details

The root cause is classified as CWE-918 (Server-Side Request Forgery), where the downloadVideoFromDownloadURL() function in objects/aVideoEncoder.json.php directly passes the attacker-supplied downloadURL parameter to a server-side HTTP fetch function (url_get_contents()) without validating the destination against an allow-list or blocking internal/private address ranges (GitHub Advisory). The attack is network-based, requires low privileges (a valid authenticated session), and no user interaction. The fix introduced an isSSRFSafeURL() function that enforces scheme restrictions (http/https only), blocks localhost and loopback addresses, private IPv4 ranges (10.x.x.x, 172.16–31.x.x, 192.168.x.x), link-local addresses (169.254.x.x including cloud metadata endpoints), and IPv6 private/local addresses, and was applied across multiple files including aVideoEncoderReceiveImage.json.php and plugin/AI/receiveAsync.json.php (AVideo Commit).

Impact

Successful exploitation allows an authenticated attacker to make the AVideo server issue HTTP requests to arbitrary URLs, including internal network services, cloud metadata endpoints (e.g., http://169.254.169.254/), and other infrastructure not directly accessible from the internet. This can result in high confidentiality and integrity impact — sensitive data such as internal API responses, credentials, or cloud instance metadata can be retrieved and potentially used for lateral movement or further compromise of the deployment environment. Availability is not directly impacted by this vulnerability (Github Advisory, GitHub Advisory).

Exploitability

No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported as of the time of disclosure (Feedly). The EPSS score is approximately 0.04% (13th percentile), indicating a low near-term probability of exploitation (Github Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported. Exploitation requires a valid authenticated account on the AVideo instance, which limits the attack surface compared to unauthenticated vulnerabilities.

Exploitation steps

  1. Obtain Authentication: Register or obtain credentials for a low-privilege user account on the target AVideo instance (versions prior to 22.0).
  2. Identify the Vulnerable Endpoint: Locate the aVideoEncoder.json.php API endpoint on the target server (e.g., https://target.example.com/objects/aVideoEncoder.json.php).
  3. Craft the SSRF Request: Authenticate to the application and send a POST or GET request to the endpoint with a malicious downloadURL parameter pointing to an internal resource, such as the cloud metadata service:
    POST /objects/aVideoEncoder.json.php HTTP/1.1
    Host: target.example.com
    Cookie: <authenticated_session_cookie>
    
    downloadURL=http://169.254.169.254/latest/meta-data/
  4. Retrieve Internal Data: The server fetches the specified URL and may return or process the response content, allowing the attacker to enumerate internal services, retrieve cloud instance metadata (e.g., IAM credentials on AWS), or probe internal APIs.
  5. Pivot for Further Compromise: Use retrieved credentials or internal service information (e.g., database endpoints, API keys) to escalate access within the deployment environment (GitHub Advisory, AVideo Commit).

Indicators of compromise

  • Network: Outbound HTTP/HTTPS requests from the AVideo server to internal IP ranges (10.x.x.x, 172.16–31.x.x, 192.168.x.x), loopback addresses (127.x.x.x), or cloud metadata endpoints (169.254.169.254) that are not part of normal application behavior.
  • Logs: AVideo application error logs (aVideoEncoder log entries) showing blocked or attempted requests to internal/private URLs if SSRF protection is active; web server access logs showing authenticated POST requests to /objects/aVideoEncoder.json.php with unusual downloadURL parameter values pointing to internal addresses.
  • Network: DNS queries from the AVideo server for internal hostnames or unusual external hostnames that resolve to private IP ranges, potentially indicating DNS rebinding attempts.
  • File System: Unexpected files written to the AVideo installation directory if the SSRF is chained with a file-write operation via a fetched resource.

Mitigation and workarounds

The vulnerability is fixed in AVideo version 22.0, which introduces the isSSRFSafeURL() validation function applied to all URL-fetching operations across affected files (AVideo Release 22.0, AVideo Commit). Administrators should upgrade to version 22.0 or later as the primary remediation. For systems that cannot be immediately patched, implement network-level egress filtering to block the AVideo server from making outbound connections to internal IP ranges and cloud metadata endpoints, and restrict access to the aVideoEncoder.json.php endpoint to trusted users only (Feedly).

Community reactions

The vulnerability received routine coverage across CVE tracking platforms and security aggregators shortly after disclosure. Social media posts on Bluesky and Mastodon noted the advisory, and it was included in at least one cybersecurity news brief (Straylight Sentinel). No significant vendor statements beyond the official GitHub security advisory, nor notable independent researcher commentary, have been identified.

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management