CVE-2026-33512: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-33512 is an unauthenticated decrypt oracle vulnerability in WWBN AVideo, an open source video platform. The API plugin exposes a decryptString action without any authentication, allowing any unauthenticated user to submit ciphertext and receive the corresponding plaintext. All versions up to and including 26.0 are affected. The vulnerability was published on March 23, 2026, and carries a CVSS v3.1 base score of 7.5 (High) (GitHub Advisory).

Technical details

The root cause is improper authentication (CWE-287) on the decryptString API endpoint (plugin/API/get.json.php?APIName=decryptString), compounded by cleartext storage of sensitive information (CWE-312), inadequate encryption strength (CWE-326), and use of a broken or risky cryptographic algorithm (CWE-327). The handler get_api_decryptString() in plugin/API/API.php (lines ~5945–5966) calls decryptString($_REQUEST['string']) and returns the result without performing any APISecret or user authorization check. Ciphertext is publicly obtainable from view/url2Embed.json.php, which returns playLink/playEmbedLink values (produced by encryptString(json_encode(...))) to any caller, providing attackers with the input needed to exploit the oracle (GitHub Advisory, Patch Commit).

Impact

Successful exploitation allows any unauthenticated network attacker to decrypt any ciphertext produced by the AVideo platform, recovering protected tokens, video links, user IDs, titles, and other metadata intended to remain confidential. This constitutes a full confidentiality breach of encrypted payloads, enabling replay attacks and potential tampering in scenarios where secrecy was assumed. Integrity and availability are not directly impacted, but exposed tokens could facilitate session hijacking or unauthorized access to protected content (GitHub Advisory).

Exploitability

A proof-of-concept exploit is publicly documented in the GitHub Security Advisory, providing concrete HTTP request sequences that require no authentication, no special privileges, and no user interaction. The EPSS score is approximately 0.033% (low automated exploitation probability at time of publication), and there is no evidence of active in-the-wild exploitation or CISA KEV catalog listing as of the report date. No threat actor attribution has been identified (GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing AVideo instances running version 26.0 or earlier using search engines (e.g., Shodan, Censys) or by checking the AVideo version endpoint.
  2. Obtain ciphertext: Send an unauthenticated GET request to the public endpoint to retrieve an encrypted payload:
    GET /view/url2Embed.json.php?url=https://example.com/video.mp4
    Extract the playLink value from the JSON response — this is the ciphertext.
  3. Submit ciphertext to decrypt oracle: Send an unauthenticated POST request to the API endpoint with the captured ciphertext:
    POST /plugin/API/get.json.php?APIName=decryptString
    Content-Type: application/x-www-form-urlencoded
    
    string=<playLink ciphertext>
  4. Recover plaintext: The response contains the decrypted JSON, including sensitive fields such as videoLink, title, users_id, and other protected metadata.
  5. Abuse recovered tokens: Use the recovered tokens or links for replay attacks, unauthorized content access, or further enumeration of user data (GitHub Advisory).

Indicators of compromise

  • Network: Unusual or repeated GET requests to /view/url2Embed.json.php from unauthenticated or unknown IP addresses, particularly followed by POST requests to /plugin/API/get.json.php?APIName=decryptString from the same source.
  • Logs: Web server access logs showing POST requests to /plugin/API/get.json.php with the APIName=decryptString parameter from unauthenticated sessions (no session cookie or API secret present); high volume of such requests may indicate automated scanning or bulk decryption attempts.
  • Application Logs: AVideo API logs recording decryptString calls without associated valid APISecret or admin user context (pre-patch behavior).

Mitigation and workarounds

The fix is available in commit 3fdeecef37bb88967a02ccc9b9acc8da95de1c13, which adds an authentication check requiring either admin status or a valid APISecret before the decryptString action is executed. Operators should upgrade AVideo to a version incorporating this patch immediately. As interim workarounds, restrict access to plugin/API/get.json.php at the web server or firewall level, and rotate encryption keys/salts to invalidate any ciphertexts that may have been exposed. The advisory also recommends replacing symmetric encryption with one-way HMAC signatures where decryption is not operationally required (GitHub Advisory, Patch Commit).

Community reactions

The vulnerability was reported by security researcher Ahmad-jarwan and published by the AVideo maintainer DanielnetoDotCom via GitHub's security advisory process. Brief mentions appeared on Mastodon (via @thehackerwire) and aggregator sites such as cvefeed.io and vuldb.com shortly after disclosure, but no significant broader media coverage or notable researcher commentary beyond the advisory itself has been identified (GitHub Advisory).

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management