CVE-2026-33238: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-33238 is a path traversal vulnerability in WWBN AVideo's listFiles.json.php endpoint that enables authenticated uploaders to enumerate private, premium, or access-controlled .mp4 files stored anywhere on the server filesystem. It affects AVideo versions up to and including 25.0 (Composer package wwbn/avideo), with version 26.0 containing the fix. The vulnerability was published on March 18, 2026, and assigned a CVSS v3.1 base score of 4.3 (Medium) (GitHub Advisory, AVideo Security Advisory).

Technical details

The root cause is CWE-22 (Improper Limitation of a Pathname to a Restricted Directory). The vulnerable code in objects/listFiles.json.php accepts a user-supplied path POST parameter and passes it directly to PHP's glob() function without calling realpath() for normalization or performing any prefix check against a permitted base directory. Because the response includes the full absolute filesystem path ($obj->path) of each matched .mp4 file, an attacker can supply arbitrary absolute paths (e.g., /var/private/premium-content/ or /) to enumerate .mp4 files anywhere readable by the web server process. Exploitation requires only a valid session with canUpload permission, which is the standard role granted to all registered video uploaders on a multi-user AVideo instance (GitHub Advisory, AVideo Security Advisory).

Impact

Successful exploitation allows any authenticated uploader to discover the filenames and full absolute filesystem paths of private, premium, or paywalled .mp4 files stored outside their permitted directory, effectively bypassing content access controls. The disclosure of full absolute paths also reveals the server's directory layout, which can facilitate follow-up attacks if additional vulnerabilities (e.g., direct file access or further path traversal weaknesses) are present. There is no integrity or availability impact; the vulnerability is limited to confidentiality loss affecting media content and server structure information (GitHub Advisory).

Exploitability

A proof-of-concept exploit consisting of concrete curl commands is publicly available in the GitHub Security Advisory (AVideo Security Advisory). There is no evidence of in-the-wild exploitation at this time, and the vulnerability has not been added to the CISA Known Exploited Vulnerabilities catalog. The EPSS score is approximately 0.036% (0.018% per GitHub Advisory), reflecting a low near-term exploitation probability. No threat actor attribution has been reported.

Exploitation steps

  1. Obtain credentials: Register or obtain credentials for any AVideo account with canUpload permission — the standard role for all video uploaders on a multi-user instance.
  2. Authenticate and capture session: Log in to the target AVideo instance and capture the PHPSESSID session cookie.
  3. Baseline enumeration (expected behavior): Send a POST request to the /listFiles endpoint with the intended upload directory to confirm the endpoint is functional:
    curl -b "PHPSESSID=<session>" -X POST https://target.avideo.site/listFiles \
      -d "path=/var/www/html/videos/"
  4. Traverse to restricted directory: Supply an arbitrary absolute path outside the permitted directory to enumerate protected .mp4 files:
    curl -b "PHPSESSID=<session>" -X POST https://target.avideo.site/listFiles \
      -d "path=/var/private/premium-content/"
    The response returns full absolute paths such as /var/private/premium-content/paywalled-video.mp4.
  5. Broad filesystem enumeration: Supply the root path to enumerate all .mp4 files visible to the web server process:
    curl -b "PHPSESSID=<session>" -X POST https://target.avideo.site/listFiles \
      -d "path=/"
  6. Map directory structure: Use the returned absolute paths to reconstruct the server's directory layout and identify targets for follow-up attacks if additional vulnerabilities exist (AVideo Security Advisory).

Indicators of compromise

  • Network: Unusual HTTP POST requests to /listFiles (or /objects/listFiles.json.php) with path parameter values pointing to directories outside the AVideo web root (e.g., /var/private/, /home/, /etc/, /).
  • Logs: Web server access logs showing repeated POST requests to the listFiles endpoint from a single authenticated session with varying path values; HTTP 200 responses to requests with non-standard path values.
  • Logs: Application logs showing requests with path parameters containing absolute paths not matching the configured systemRootPath . 'videos' directory.
  • Network: Responses from the server containing JSON arrays with path fields referencing filesystem locations outside the expected video upload directory (AVideo Security Advisory).

Mitigation and workarounds

Upgrade AVideo to version 26.0 or later, which resolves the vulnerability by using realpath() to normalize the supplied path and rejecting any path that does not begin with the permitted base directory ($global['systemRootPath'] . 'videos/'), returning HTTP 403 for disallowed paths (AVideo Patch Commit). As a complementary measure, restrict canUpload permissions to trusted users only on multi-user deployments, and ensure premium or private video files are stored in directories protected by OS-level access controls that prevent the web server process from reading them. Implementing filesystem-level access controls provides defense-in-depth even if the application-level fix is applied (GitHub Advisory).

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management