
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33297 is an authentication bypass vulnerability in WWBN AVideo affecting the setPassword.json.php endpoint of the CustomizeUser plugin. When an administrator sets a channel password using a non-numeric (alphanumeric) string, PHP's intval() function silently coerces the value to 0, causing any unauthenticated or unprivileged user to bypass channel-level access control simply by entering 0 as the password. All AVideo versions up to and including 25.0 (Composer package wwbn/avideo) are affected; version 26.0 contains the fix. The vulnerability was published on March 18, 2026, and assigned a CVSS v3.1 base score of 9.1 (Critical) by Feedly and a CVSS v4.0 base score of 5.1 (Moderate) by GitHub Advisory (GitHub Advisory, AVideo Advisory).
The root cause is a logic error classified as CWE-639 (Authorization Bypass Through User-Controlled Key): the setPassword.json.php endpoint applies intval() to the ProfilePassword request parameter before passing it to User::setProfilePassword(). Because intval('secretabc123') returns 0 in PHP, any alphanumeric password is silently stored as the integer 0 in the database, with no error or warning surfaced to the administrator. The vulnerable code path is: $obj->ProfilePassword = intval(@$_REQUEST['ProfilePassword']); followed by User::setProfilePassword($users_id, $obj->ProfilePassword);. The fix (commit 7a6a946) replaces intval() with strval() to preserve the password as a string (AVideo Advisory, Fix Commit).
Successful exploitation allows any unauthenticated or unprivileged network user to access password-protected channel content by submitting 0 as the channel password, completely defeating the channel password protection feature for all channels configured with non-numeric passwords. The impact is scoped to channel-level confidentiality and integrity — it does not enable account takeover, privilege escalation, or remote code execution. However, any sensitive or restricted video content intended to be gated behind a password is fully exposed to unauthorized viewers (GitHub Advisory).
A proof-of-concept exploit is publicly available in the GitHub Security Advisory, including specific curl commands and a Python script demonstrating the full attack flow (AVideo Advisory). The vulnerability requires no user interaction and no privileges to exploit from the attacker's perspective (the password coercion occurs when any admin sets a non-numeric password). There is no evidence of in-the-wild exploitation at this time, and the CVE is not listed in the CISA KEV catalog. The EPSS score is approximately 0.027% (0.055% per GitHub Advisory), indicating low current exploitation probability (GitHub Advisory).
secretPassword123), the password is already stored as 0 in the database. No attacker action is needed for this step.password=0 to gain access to the protected channel content:curl -s -X POST "https://target.example.com/channel_password_check_endpoint" \
-d "users_id=42&password=0"/plugin/CustomizeUser/setPassword.json.php with ProfilePassword values containing non-numeric characters; POST requests to channel password check endpoints with password=0 from unauthenticated or low-privilege users.200 OK responses to channel password check endpoints where the submitted password parameter is 0; access log entries for /plugin/CustomizeUser/setPassword.json.php from admin sessions followed shortly by access from unauthenticated IPs.0 for channels that administrators intended to protect with alphanumeric passwords.The primary remediation is to update AVideo to version 26.0 or later, which replaces the vulnerable intval() call with strval() in setPassword.json.php (commit 7a6a946) (Fix Commit). As an interim workaround prior to patching, administrators should audit all password-protected channels and reset channel passwords to purely numeric values, or remove password protection and implement alternative access controls (e.g., network-level restrictions or authentication walls). Administrators should also be aware that any channel for which an alphanumeric password was previously set is currently protected only by the trivially guessable value 0 (GitHub Advisory).
The vulnerability was reported by security researcher fg0x0 and published by the AVideo maintainer DanielnetoDotCom on March 18, 2026. Coverage appeared on The Hacker Wire, which highlighted the critical authentication bypass nature of the flaw (The Hacker Wire). Additional coverage was published by Yazoul.net, framing it as an access control bypass requiring immediate patching (Yazoul Advisory). Community discussion noted the irony that well-intentioned administrators unknowingly weaken security by setting what they believe are strong alphanumeric passwords.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."