CVE-2026-33297: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-33297 is an authentication bypass vulnerability in WWBN AVideo affecting the setPassword.json.php endpoint of the CustomizeUser plugin. When an administrator sets a channel password using a non-numeric (alphanumeric) string, PHP's intval() function silently coerces the value to 0, causing any unauthenticated or unprivileged user to bypass channel-level access control simply by entering 0 as the password. All AVideo versions up to and including 25.0 (Composer package wwbn/avideo) are affected; version 26.0 contains the fix. The vulnerability was published on March 18, 2026, and assigned a CVSS v3.1 base score of 9.1 (Critical) by Feedly and a CVSS v4.0 base score of 5.1 (Moderate) by GitHub Advisory (GitHub Advisory, AVideo Advisory).

Technical details

The root cause is a logic error classified as CWE-639 (Authorization Bypass Through User-Controlled Key): the setPassword.json.php endpoint applies intval() to the ProfilePassword request parameter before passing it to User::setProfilePassword(). Because intval('secretabc123') returns 0 in PHP, any alphanumeric password is silently stored as the integer 0 in the database, with no error or warning surfaced to the administrator. The vulnerable code path is: $obj->ProfilePassword = intval(@$_REQUEST['ProfilePassword']); followed by User::setProfilePassword($users_id, $obj->ProfilePassword);. The fix (commit 7a6a946) replaces intval() with strval() to preserve the password as a string (AVideo Advisory, Fix Commit).

Impact

Successful exploitation allows any unauthenticated or unprivileged network user to access password-protected channel content by submitting 0 as the channel password, completely defeating the channel password protection feature for all channels configured with non-numeric passwords. The impact is scoped to channel-level confidentiality and integrity — it does not enable account takeover, privilege escalation, or remote code execution. However, any sensitive or restricted video content intended to be gated behind a password is fully exposed to unauthorized viewers (GitHub Advisory).

Exploitability

A proof-of-concept exploit is publicly available in the GitHub Security Advisory, including specific curl commands and a Python script demonstrating the full attack flow (AVideo Advisory). The vulnerability requires no user interaction and no privileges to exploit from the attacker's perspective (the password coercion occurs when any admin sets a non-numeric password). There is no evidence of in-the-wild exploitation at this time, and the CVE is not listed in the CISA KEV catalog. The EPSS score is approximately 0.027% (0.055% per GitHub Advisory), indicating low current exploitation probability (GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify AVideo instances running version 25.0 or earlier using Shodan, Censys, or similar tools by searching for AVideo-specific HTTP response headers or page content.
  2. Confirm vulnerability: Verify the target is running a vulnerable version by checking the AVideo version endpoint or reviewing publicly accessible pages.
  3. Trigger password coercion (optional — passive): If an administrator has already set a channel password using an alphanumeric string (e.g., secretPassword123), the password is already stored as 0 in the database. No attacker action is needed for this step.
  4. Bypass channel password: Send a POST request to the channel password check endpoint with password=0 to gain access to the protected channel content:
curl -s -X POST "https://target.example.com/channel_password_check_endpoint" \
  -d "users_id=42&password=0"
  1. Access protected content: Upon successful bypass, browse or download all content within the password-protected channel that was intended to be restricted (AVideo Advisory).

Indicators of compromise

  • Network: Repeated POST requests to /plugin/CustomizeUser/setPassword.json.php with ProfilePassword values containing non-numeric characters; POST requests to channel password check endpoints with password=0 from unauthenticated or low-privilege users.
  • Logs: Web server access logs showing successful 200 OK responses to channel password check endpoints where the submitted password parameter is 0; access log entries for /plugin/CustomizeUser/setPassword.json.php from admin sessions followed shortly by access from unauthenticated IPs.
  • Database: Channel password fields in the AVideo database storing the integer value 0 for channels that administrators intended to protect with alphanumeric passwords.

Mitigation and workarounds

The primary remediation is to update AVideo to version 26.0 or later, which replaces the vulnerable intval() call with strval() in setPassword.json.php (commit 7a6a946) (Fix Commit). As an interim workaround prior to patching, administrators should audit all password-protected channels and reset channel passwords to purely numeric values, or remove password protection and implement alternative access controls (e.g., network-level restrictions or authentication walls). Administrators should also be aware that any channel for which an alphanumeric password was previously set is currently protected only by the trivially guessable value 0 (GitHub Advisory).

Community reactions

The vulnerability was reported by security researcher fg0x0 and published by the AVideo maintainer DanielnetoDotCom on March 18, 2026. Coverage appeared on The Hacker Wire, which highlighted the critical authentication bypass nature of the flaw (The Hacker Wire). Additional coverage was published by Yazoul.net, framing it as an access control bypass requiring immediate patching (Yazoul Advisory). Community discussion noted the irony that well-intentioned administrators unknowingly weaken security by setting what they believe are strong alphanumeric passwords.

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management