CVE-2026-29093: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-29093 is a misconfiguration vulnerability in WWBN AVideo (the open-source video platform) in which the official docker-compose.yml publishes the memcached service on host port 11211 (0.0.0.0:11211) with no authentication, while the Dockerfile configures PHP to store all user sessions in that memcached instance. This allows any network-reachable attacker to read, modify, or flush session data without any credentials. All AVideo versions prior to 24.0 are affected. The vulnerability was published on March 3, 2026, and assigned a CVSS v3.1 score of 8.1 (High) by the vendor advisory, though Feedly's aggregated data reflects a score of 9.8 (Critical) (GitHub Advisory, AVideo Advisory).

Technical details

The root cause is a combination of CWE-668 (Exposure of Resource to Wrong Sphere) and CWE-287 (Improper Authentication): the docker-compose.yml binds memcached to 0.0.0.0:11211 on the Docker host without the -S SASL authentication flag or -l 127.0.0.1 interface restriction, while the Dockerfile (lines 150–151) sets session.save_handler = memcached and session.save_path = "memcached:11211". The session data stored in memcached includes user IDs, email addresses, admin flags ($_SESSION['user']['isAdmin']), and password hashes ($_SESSION['user']['passhash']), all of which are readable and writable by any client that can reach port 11211. Notably, the database services in the same docker-compose.yml are correctly isolated with no ports: directive, confirming the memcached exposure is an oversight. A proof-of-concept using standard nc commands is publicly available in the advisory (GitHub Advisory, AVideo Advisory).

Impact

Successful exploitation enables an unauthenticated attacker to hijack any active user session — including administrator accounts — by reading session IDs from memcached and replaying them as PHPSESSID cookies. An attacker can also escalate privileges by writing a modified session with isAdmin set to a truthy value, extract password hashes for offline cracking, or execute a one-command denial of service by issuing flush_all to destroy all active sessions and force mass re-authentication. Additionally, the stats command exposes server reconnaissance data including uptime, memory usage, and connection counts (GitHub Advisory).

Exploitability

A proof-of-concept exploit using standard Unix tools (nc, memcached text protocol commands) is publicly documented in the GitHub Security Advisory, requiring no special tooling or authentication (GitHub Advisory). Exploitation requires that port 11211 be network-reachable from the attacker, which depends on external firewall or security group configuration — the vendor advisory rates attack complexity as High for this reason. There is no confirmed evidence of in-the-wild exploitation at this time, and the EPSS score is approximately 0.044% (14th percentile) (GitHub Advisory). The vulnerability is not currently listed in the CISA KEV catalog.

Exploitation steps

  1. Reconnaissance: Scan the target host for open port 11211 using tools like nmap or masscan to confirm the memcached service is network-reachable.
  2. Verify access: Connect to memcached with no credentials using echo -e "stats\r" | nc TARGET 11211 — a successful response confirms unauthenticated access and reveals server uptime, memory, and connection statistics.
  3. Enumerate session keys: Run echo -e "stats items\r" | nc TARGET 11211 to identify slab classes, then echo -e "stats cachedump 1 100\r" | nc TARGET 11211 to list session key names (format: memc.sess.key.<sessionid>).
  4. Read session data: Retrieve a session with echo -e "get memc.sess.key.abc123sessionid\r" | nc TARGET 11211 to obtain serialized PHP session data containing user ID, email, admin flag, and password hash.
  5. Session hijacking: Extract the session ID from step 4 and set it as the PHPSESSID cookie in a browser to impersonate the victim user, including any administrator.
  6. Privilege escalation: Use the memcached set command to overwrite a session entry with modified data where isAdmin is set to a truthy value, granting admin access to a controlled session.
  7. Credential extraction: Parse the passhash field from retrieved session data and submit it to an offline password cracking tool (e.g., hashcat) for credential recovery.
  8. Denial of service (optional): Issue echo -e "flush_all\r" | nc TARGET 11211 to destroy all active sessions, forcing every logged-in user to re-authenticate (GitHub Advisory, AVideo Advisory).

Indicators of compromise

  • Network: Unexpected inbound TCP connections to port 11211 from external or untrusted IP addresses; memcached text-protocol commands (stats, stats items, stats cachedump, get, set, flush_all) observed in network traffic captures on port 11211.
  • Logs: Web server access logs showing PHPSESSID cookies from IP addresses that never performed a login request; sudden mass session invalidation events (all users logged out simultaneously) indicating a flush_all command was issued.
  • Application Behavior: Unexpected admin-level actions performed by accounts with no prior admin activity; multiple accounts accessed from the same IP address in rapid succession (session replay); user accounts reporting unexpected logouts across the entire platform.
  • File System / Configuration: Presence of MEMCACHE_PORT=11211 in env.example or active environment with the ports: directive in docker-compose.yml binding memcached to 0.0.0.0:11211 confirms vulnerable configuration (GitHub Advisory).

Mitigation and workarounds

Upgrade AVideo to version 24.0 or later, which addresses this misconfiguration (AVideo Release 24.0). The preferred immediate fix is to remove the ports: directive from the memcached service in docker-compose.yml entirely, since memcached is only needed internally via Docker's app_net bridge network. If host-level access is required for debugging, bind memcached to localhost only by changing the port mapping to "127.0.0.1:${MEMCACHE_PORT:-11211}:11211". As defense-in-depth, enable SASL authentication on memcached by adding the -S flag and updating session.save_path with credentials. Until patching is complete, implement network-level firewall rules to block external access to port 11211 and force all users to re-authenticate after the fix is deployed (GitHub Advisory, AVideo Advisory).

Community reactions

The vulnerability was discovered and reported by bugbunny.ai and published by the AVideo maintainer (DanielnetoDotCom) on March 3, 2026 (GitHub Advisory). Social media activity was observed on Bluesky and Mastodon shortly after disclosure, with accounts such as @thehackerwire amplifying the advisory. Coverage also appeared on threat intelligence aggregators including Vulners, CVEFeed, and Infinit Security's blog, which published a dedicated write-up (Infinit Security). Red Hat also tracked the CVE in their security advisory database as of March 7, 2026.

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management