
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33512 is an unauthenticated decrypt oracle vulnerability in WWBN AVideo, an open source video platform. The API plugin exposes a decryptString action without any authentication, allowing any unauthenticated user to submit ciphertext and receive the corresponding plaintext. All versions up to and including 26.0 are affected. The vulnerability was published on March 23, 2026, and carries a CVSS v3.1 base score of 7.5 (High) (GitHub Advisory).
The root cause is improper authentication (CWE-287) on the decryptString API endpoint (plugin/API/get.json.php?APIName=decryptString), compounded by cleartext storage of sensitive information (CWE-312), inadequate encryption strength (CWE-326), and use of a broken or risky cryptographic algorithm (CWE-327). The handler get_api_decryptString() in plugin/API/API.php (lines ~5945–5966) calls decryptString($_REQUEST['string']) and returns the result without performing any APISecret or user authorization check. Ciphertext is publicly obtainable from view/url2Embed.json.php, which returns playLink/playEmbedLink values (produced by encryptString(json_encode(...))) to any caller, providing attackers with the input needed to exploit the oracle (GitHub Advisory, Patch Commit).
Successful exploitation allows any unauthenticated network attacker to decrypt any ciphertext produced by the AVideo platform, recovering protected tokens, video links, user IDs, titles, and other metadata intended to remain confidential. This constitutes a full confidentiality breach of encrypted payloads, enabling replay attacks and potential tampering in scenarios where secrecy was assumed. Integrity and availability are not directly impacted, but exposed tokens could facilitate session hijacking or unauthorized access to protected content (GitHub Advisory).
A proof-of-concept exploit is publicly documented in the GitHub Security Advisory, providing concrete HTTP request sequences that require no authentication, no special privileges, and no user interaction. The EPSS score is approximately 0.033% (low automated exploitation probability at time of publication), and there is no evidence of active in-the-wild exploitation or CISA KEV catalog listing as of the report date. No threat actor attribution has been identified (GitHub Advisory).
GET /view/url2Embed.json.php?url=https://example.com/video.mp4Extract the playLink value from the JSON response — this is the ciphertext.POST /plugin/API/get.json.php?APIName=decryptString
Content-Type: application/x-www-form-urlencoded
string=<playLink ciphertext>videoLink, title, users_id, and other protected metadata./view/url2Embed.json.php from unauthenticated or unknown IP addresses, particularly followed by POST requests to /plugin/API/get.json.php?APIName=decryptString from the same source./plugin/API/get.json.php with the APIName=decryptString parameter from unauthenticated sessions (no session cookie or API secret present); high volume of such requests may indicate automated scanning or bulk decryption attempts.decryptString calls without associated valid APISecret or admin user context (pre-patch behavior).The fix is available in commit 3fdeecef37bb88967a02ccc9b9acc8da95de1c13, which adds an authentication check requiring either admin status or a valid APISecret before the decryptString action is executed. Operators should upgrade AVideo to a version incorporating this patch immediately. As interim workarounds, restrict access to plugin/API/get.json.php at the web server or firewall level, and rotate encryption keys/salts to invalidate any ciphertexts that may have been exposed. The advisory also recommends replacing symmetric encryption with one-way HMAC signatures where decryption is not operationally required (GitHub Advisory, Patch Commit).
The vulnerability was reported by security researcher Ahmad-jarwan and published by the AVideo maintainer DanielnetoDotCom via GitHub's security advisory process. Brief mentions appeared on Mastodon (via @thehackerwire) and aggregator sites such as cvefeed.io and vuldb.com shortly after disclosure, but no significant broader media coverage or notable researcher commentary beyond the advisory itself has been identified (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."