
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33041 is an unauthenticated password hash oracle vulnerability in WWBN AVideo, an open source video platform. The /objects/encryptPass.json.php endpoint exposes the application's password hashing algorithm to any unauthenticated user, allowing attackers to submit arbitrary passwords and receive their hashed equivalents. This affects AVideo versions 25.0 and below; the issue was fixed in version 26.0. It carries a CVSS v3.1 base score of 5.3 (Medium) (GitHub Advisory, AVideo Advisory).
The root cause is improper access control (CWE-200: Exposure of Sensitive Information to an Unauthorized Actor) in objects/encryptPass.json.php, which accepts a pass parameter via $_REQUEST and returns the hashed password without any authentication check. The encryptPassword() function applies a weak hash chain — md5(hash('whirlpool', sha1($password))) — with no salt by default (the encryptPasswordsWithSalt option is disabled), making hashes deterministic and identical to those stored in the database. An attacker can exploit this endpoint as a live oracle to build rainbow tables against any password list, dramatically accelerating offline cracking of database hashes obtained through secondary means such as SQL injection or backup exposure. The vulnerability requires no privileges or user interaction and is exploitable over the network (GitHub Advisory, AVideo Advisory).
The primary impact is confidentiality: the endpoint leaks the application's exact hashing algorithm and cryptographic configuration (including whether salting is enabled) to any unauthenticated network attacker. If an attacker separately obtains database password hashes — via SQL injection, exposed backups, or other means — they can use this oracle to rapidly crack those hashes without needing to reverse-engineer the algorithm. Successful password cracking could lead to account takeover, unauthorized access to user and administrator accounts, and potential lateral movement within the platform or connected systems (GitHub Advisory).
A proof-of-concept exploit is publicly documented in the GitHub Security Advisory, consisting of simple curl commands and a bash loop to build a rainbow table against a live target. No authentication or special privileges are required to exploit the endpoint. There is no evidence of active in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. The EPSS score is approximately 0.03% (8th percentile), indicating low near-term exploitation probability (GitHub Advisory, AVideo Advisory).
curl 'https://TARGET/objects/encryptPass.json.php?pass=test'A JSON response containing encryptedPassword confirms the endpoint is exposed.for pass in $(cat rockyou-top1000.txt); do
curl -s "https://TARGET/objects/encryptPass.json.php?pass=$pass"
done/objects/encryptPass.json.php from a single or rotating IP address, especially with varying pass parameter values; automated request patterns consistent with wordlist iteration.encryptPass.json.php with sequential or dictionary-based pass values; requests originating from non-administrative IPs or unexpected geographic locations.encryptPass.json.php endpoint; HTTP 200 responses to unauthenticated requests on unpatched instances.Upgrade WWBN AVideo to version 26.0 or later, which enforces authentication (admin session or HMAC token) and rate limiting (20 requests per 5 minutes per IP) on the encryptPass.json.php endpoint (AVideo Patch Commit). If immediate upgrade is not possible, restrict network access to /objects/encryptPass.json.php via web server configuration (e.g., deny unauthenticated access via .htaccess or nginx rules), or remove the file entirely if not required. Additionally, review access logs for unauthorized use of this endpoint and consider enabling password salting in AVideo's advanced settings to reduce the impact of any hash exposure (GitHub Advisory).
The vulnerability was reported by researcher 'offensiveee' and published by the AVideo maintainer (DanielnetoDotCom) on March 16, 2026. The fix was committed promptly alongside regression tests to prevent reintroduction. No significant broader media coverage or notable community commentary beyond the GitHub advisory has been identified (GitHub Advisory, AVideo Patch Commit).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."