
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-29093 is a misconfiguration vulnerability in WWBN AVideo (the open-source video platform) in which the official docker-compose.yml publishes the memcached service on host port 11211 (0.0.0.0:11211) with no authentication, while the Dockerfile configures PHP to store all user sessions in that memcached instance. This allows any network-reachable attacker to read, modify, or flush session data without any credentials. All AVideo versions prior to 24.0 are affected. The vulnerability was published on March 3, 2026, and assigned a CVSS v3.1 score of 8.1 (High) by the vendor advisory, though Feedly's aggregated data reflects a score of 9.8 (Critical) (GitHub Advisory, AVideo Advisory).
The root cause is a combination of CWE-668 (Exposure of Resource to Wrong Sphere) and CWE-287 (Improper Authentication): the docker-compose.yml binds memcached to 0.0.0.0:11211 on the Docker host without the -S SASL authentication flag or -l 127.0.0.1 interface restriction, while the Dockerfile (lines 150–151) sets session.save_handler = memcached and session.save_path = "memcached:11211". The session data stored in memcached includes user IDs, email addresses, admin flags ($_SESSION['user']['isAdmin']), and password hashes ($_SESSION['user']['passhash']), all of which are readable and writable by any client that can reach port 11211. Notably, the database services in the same docker-compose.yml are correctly isolated with no ports: directive, confirming the memcached exposure is an oversight. A proof-of-concept using standard nc commands is publicly available in the advisory (GitHub Advisory, AVideo Advisory).
Successful exploitation enables an unauthenticated attacker to hijack any active user session — including administrator accounts — by reading session IDs from memcached and replaying them as PHPSESSID cookies. An attacker can also escalate privileges by writing a modified session with isAdmin set to a truthy value, extract password hashes for offline cracking, or execute a one-command denial of service by issuing flush_all to destroy all active sessions and force mass re-authentication. Additionally, the stats command exposes server reconnaissance data including uptime, memory usage, and connection counts (GitHub Advisory).
A proof-of-concept exploit using standard Unix tools (nc, memcached text protocol commands) is publicly documented in the GitHub Security Advisory, requiring no special tooling or authentication (GitHub Advisory). Exploitation requires that port 11211 be network-reachable from the attacker, which depends on external firewall or security group configuration — the vendor advisory rates attack complexity as High for this reason. There is no confirmed evidence of in-the-wild exploitation at this time, and the EPSS score is approximately 0.044% (14th percentile) (GitHub Advisory). The vulnerability is not currently listed in the CISA KEV catalog.
nmap or masscan to confirm the memcached service is network-reachable.echo -e "stats\r" | nc TARGET 11211 — a successful response confirms unauthenticated access and reveals server uptime, memory, and connection statistics.echo -e "stats items\r" | nc TARGET 11211 to identify slab classes, then echo -e "stats cachedump 1 100\r" | nc TARGET 11211 to list session key names (format: memc.sess.key.<sessionid>).echo -e "get memc.sess.key.abc123sessionid\r" | nc TARGET 11211 to obtain serialized PHP session data containing user ID, email, admin flag, and password hash.PHPSESSID cookie in a browser to impersonate the victim user, including any administrator.set command to overwrite a session entry with modified data where isAdmin is set to a truthy value, granting admin access to a controlled session.passhash field from retrieved session data and submit it to an offline password cracking tool (e.g., hashcat) for credential recovery.echo -e "flush_all\r" | nc TARGET 11211 to destroy all active sessions, forcing every logged-in user to re-authenticate (GitHub Advisory, AVideo Advisory).stats, stats items, stats cachedump, get, set, flush_all) observed in network traffic captures on port 11211.PHPSESSID cookies from IP addresses that never performed a login request; sudden mass session invalidation events (all users logged out simultaneously) indicating a flush_all command was issued.MEMCACHE_PORT=11211 in env.example or active environment with the ports: directive in docker-compose.yml binding memcached to 0.0.0.0:11211 confirms vulnerable configuration (GitHub Advisory).Upgrade AVideo to version 24.0 or later, which addresses this misconfiguration (AVideo Release 24.0). The preferred immediate fix is to remove the ports: directive from the memcached service in docker-compose.yml entirely, since memcached is only needed internally via Docker's app_net bridge network. If host-level access is required for debugging, bind memcached to localhost only by changing the port mapping to "127.0.0.1:${MEMCACHE_PORT:-11211}:11211". As defense-in-depth, enable SASL authentication on memcached by adding the -S flag and updating session.save_path with credentials. Until patching is complete, implement network-level firewall rules to block external access to port 11211 and force all users to re-authenticate after the fix is deployed (GitHub Advisory, AVideo Advisory).
The vulnerability was discovered and reported by bugbunny.ai and published by the AVideo maintainer (DanielnetoDotCom) on March 3, 2026 (GitHub Advisory). Social media activity was observed on Bluesky and Mastodon shortly after disclosure, with accounts such as @thehackerwire amplifying the advisory. Coverage also appeared on threat intelligence aggregators including Vulners, CVEFeed, and Infinit Security's blog, which published a dedicated write-up (Infinit Security). Red Hat also tracked the CVE in their security advisory database as of March 7, 2026.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."