CVE-2026-28502: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-28502 is an authenticated Remote Code Execution (RCE) vulnerability in WWBN AVideo, an open source video platform, affecting all versions prior to 24.0. The flaw resides in the plugin upload/import functionality, where insufficient validation of ZIP archive contents allows an authenticated administrator to upload a malicious archive containing executable PHP files that are extracted directly into a web-accessible plugin directory. The vulnerability was published on March 6, 2026, and patched in version 24.0 released February 27, 2026. It carries a CVSS v3.1 base score of 8.8 (High) and a CVSS v4.0 base score of 9.3 (Critical) (GitHub Advisory, Feedly).

Technical details

The root cause is CWE-434 (Unrestricted Upload of File with Dangerous Type). In the vulnerable code (objects/pluginImport.json.php), the application validated only that the uploaded file had a .zip extension but performed no inspection of the archive's contents. The ZIP was then extracted directly into the web-accessible plugin/ directory using exec("unzip {$path} -d {$destination}"), with no filtering of dangerous file types (e.g., .php, .phtml, .phar) or path traversal checks. This allowed an attacker to place arbitrary PHP web shells in a publicly reachable directory and trigger execution via a simple HTTP request. The fix in version 24.0 replaces the exec()-based extraction with PHP's ZipArchive class, adds strict allowlisting of file types, enforces single-directory structure, validates plugin class structure, and performs post-extraction path verification (GitHub Commit, GitHub Advisory).

Impact

Successful exploitation grants an attacker arbitrary PHP code execution on the server with the privileges of the web server process, resulting in full system compromise. This includes complete loss of confidentiality (unauthorized access to all server data, credentials, and media), integrity (ability to modify or delete files and database content), and availability (potential to crash or disable the service). The attacker could leverage the compromised server as a pivot point for lateral movement within the internal network, exfiltrate sensitive user data, or establish persistent backdoors (GitHub Advisory, Feedly).

Exploitability

No public proof-of-concept exploit code has been identified, and there is no evidence of in-the-wild exploitation at this time (Feedly). Exploitation requires authenticated administrator-level access, which limits the attack surface compared to unauthenticated vulnerabilities. The EPSS score is approximately 0.464%, reflecting a currently low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The vulnerability was reported by researcher arkmarta (GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing AVideo instances running versions prior to 24.0 using search engines (Shodan, Censys) or by checking the AVideo version disclosure on the login or admin pages.
  2. Obtain administrator credentials: Acquire valid administrator credentials through phishing, credential stuffing, or other means, as exploitation requires an authenticated admin session.
  3. Craft malicious ZIP archive: Create a ZIP file containing a PHP web shell (e.g., shell.php with <?php system($_GET['cmd']); ?>) placed inside a directory structure that mimics a plugin package (e.g., myplugin/shell.php).
  4. Upload the malicious ZIP: Log in to the AVideo admin panel and navigate to the plugin import/upload functionality. Submit the crafted ZIP archive via the plugin upload form targeting the objects/pluginImport.json.php endpoint.
  5. Trigger extraction: The vulnerable application extracts the ZIP contents directly into the web-accessible plugin/ directory without validating file types.
  6. Execute arbitrary code: Access the uploaded web shell via a browser or curl request (e.g., https://target/plugin/myplugin/shell.php?cmd=id) to execute arbitrary OS commands on the server with web server privileges (GitHub Commit, GitHub Advisory).

Indicators of compromise

  • Network: Unexpected HTTP POST requests to /objects/pluginImport.json.php from unusual source IPs or at unusual times; subsequent HTTP GET/POST requests to newly created files under the /plugin/ directory path.
  • File System: Presence of unexpected .php files (especially with names like shell.php, cmd.php, or random strings) within the AVideo plugin/ directory; newly created plugin subdirectories not corresponding to legitimate installed plugins.
  • Logs: Web server access logs showing POST requests to pluginImport.json.php followed by requests to previously non-existent PHP files under /plugin/; error logs showing unusual PHP execution or system command output.
  • Process: Unusual child processes spawned by the PHP-FPM or Apache/Nginx worker process (e.g., bash, sh, curl, wget, python) that are not part of normal AVideo operation (GitHub Commit, GitHub Advisory).

Mitigation and workarounds

Upgrade WWBN AVideo to version 24.0 or later, which introduces comprehensive ZIP content validation, safe extraction via PHP's ZipArchive, and strict file type filtering (AVideo Release). If an immediate upgrade is not possible, disable the plugin upload/import functionality entirely, or configure the web server (Apache/Nginx) to deny execution of PHP files within the plugin/ upload directory using appropriate server directives. Additionally, restrict administrator account access to trusted personnel only and enforce multi-factor authentication on admin accounts (GitHub Advisory).

Community reactions

The vulnerability was published by the AVideo maintainer DanielnetoDotCom via a GitHub Security Advisory on February 28, 2026, crediting researcher arkmarta for the report (GitHub Advisory). Security news outlet SecurityOnline.info covered the vulnerability as part of a broader report on critical AVideo vulnerabilities spanning SQL injection to RCE (SecurityOnline). Community discussion has been limited, with no significant social media controversy or widespread threat actor commentary observed at this time.

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management