CVE-2026-30885: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-30885 is an unauthenticated Insecure Direct Object Reference (IDOR) vulnerability in WWBN AVideo, an open-source video platform, that allows any unauthenticated visitor to retrieve playlist names, video IDs, and playlist status for any user on the platform. The vulnerability affects all AVideo versions prior to 25.0 and was disclosed on March 6, 2026, by researchers Akokonunes and neo-ai-engineer via a GitHub Security Advisory (Github Advisory). It carries a CVSS v3.1 base score of 5.3 (Medium) and a CVSS v4.0 base score of 5.5 (Medium) (Github Advisory).

Technical details

The root cause is the complete absence of authentication and authorization checks in the /objects/playlistsFromUser.json.php endpoint (CWE-306: Missing Authentication for Critical Function; CWE-862: Missing Authorization; CWE-639: Authorization Bypass Through User-Controlled Key). The endpoint accepts a users_id GET parameter and directly passes it to PlayList::getAllFromUser() without calling User::isLogged() or verifying that the requesting user matches the target users_id, making it a classic IDOR (Github Advisory). The same pattern was also present in the related objects/playlistsFromUserVideos.json.php endpoint, which was patched simultaneously (AVideo Commit). No special tools or privileges are required — a simple unauthenticated HTTP GET request is sufficient to exploit the flaw.

Impact

Successful exploitation results in a confidentiality breach: any unauthenticated attacker can enumerate valid user IDs by iterating through the users_id parameter and retrieve all playlist names, video IDs, and playlist statuses for every user on the platform (Github Advisory). There is no integrity or availability impact. The exposed data can reveal private content preferences and user interests, enabling targeted social engineering attacks or serving as reconnaissance for further exploitation of the platform or its users.

Exploitability

A public proof-of-concept exploit is available in the form of a simple curl command documented in the GitHub Security Advisory: curl "https://TARGET/objects/playlistsFromUser.json.php?users_id=1" (AVideo Advisory). The EPSS score is approximately 0.076–0.118%, indicating a low but non-negligible probability of exploitation in the wild within 30 days. There is no evidence of active in-the-wild exploitation or threat actor attribution at this time, and the CVE is not listed in the CISA KEV catalog (Github Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing AVideo instances (versions prior to 25.0) using search engines, Shodan, or Censys by searching for AVideo-specific page titles or paths.
  2. Confirm vulnerability: Send an unauthenticated GET request to the target endpoint to verify it returns data without requiring a session or credentials:
    curl "https://TARGET/objects/playlistsFromUser.json.php?users_id=1"
  3. User enumeration: Iterate through sequential integer values of users_id (e.g., 1, 2, 3, ...) to identify valid user accounts — a non-empty JSON response indicates a valid user ID.
  4. Data harvesting: For each valid users_id, collect playlist names, video IDs, and playlist statuses to build a profile of user interests and private content preferences.
  5. Leverage gathered intelligence: Use the harvested user data for social engineering, phishing, or as reconnaissance for further attacks against identified users or the platform (AVideo Advisory).

Indicators of compromise

  • Network: High volume of unauthenticated GET requests to /objects/playlistsFromUser.json.php with sequentially incrementing users_id values from a single or small set of IP addresses.
  • Network: Similar sequential enumeration requests to /objects/playlistsFromUserVideos.json.php with varying users_id parameters.
  • Logs: Web server access logs showing repeated requests to playlistsFromUser.json.php?users_id=<integer> without any associated session cookie or authentication header, particularly from automated user-agent strings.
  • Logs: Rapid succession of requests (e.g., hundreds per minute) to the above endpoints from the same source IP, indicative of automated enumeration scripts (AVideo Advisory).

Mitigation and workarounds

The vulnerability is fixed in AVideo version 25.0. The patch adds a visibility check so that only the playlist owner or an administrator can retrieve non-public playlists; unauthenticated or unauthorized requests are restricted to public playlists only (AVideo Commit). Administrators unable to upgrade immediately should consider blocking unauthenticated access to the /objects/playlistsFromUser.json.php and /objects/playlistsFromUserVideos.json.php endpoints via web server configuration (e.g., requiring authentication at the reverse proxy level). Upgrading to version 25.0 or later is the recommended long-term remediation (Github Advisory).

Community reactions

The vulnerability was reported by researchers Akokonunes and neo-ai-engineer and published as a GitHub Security Advisory on March 6, 2026, with the fix committed by the AVideo maintainer (DanielnetoDotCom) shortly after (AVideo Advisory). The issue received coverage from several vulnerability tracking and threat intelligence platforms including CVEFeed, VulDB, and Radar by Offseq, reflecting standard community awareness for a medium-severity open-source disclosure. No significant vendor statements beyond the advisory or notable researcher commentary beyond the original report have been identified.

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management