CVE-2026-33649: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-33649 is a GET-based Cross-Site Request Forgery (CSRF) vulnerability in WWBN AVideo, an open source video platform, that enables privilege escalation via arbitrary permission modification. The vulnerability affects all versions up to and including 26.0 (the GitHub advisory notes ≤ 27.0 for the repository advisory). It was published on March 22–23, 2026, with no patched version available as of publication. The CVSS v3.1 base score is 8.1 (High) per the GitHub Advisory Database, or 8.8 (High) per NVD scoring (GitHub Advisory, GHSA Advisory).

Technical details

The vulnerability (CWE-352) stems from three compounding weaknesses in AVideo's codebase. First, plugin/Permissions/setPermission.json.php uses PHP's $_REQUEST superglobal instead of $_POST, meaning it accepts GET parameters for a state-changing operation. Second, the endpoint performs only an User::isAdmin() check and omits the isGlobalTokenValid() CSRF token validation that other state-mutating endpoints (e.g., saveSort.json.php, pluginImport.json.php) enforce. Third, objects/include_config.php explicitly sets session.cookie_samesite=None to support cross-origin iframe embedding, which causes the admin's session cookie to be sent on cross-origin requests — including those triggered by <img> tags on attacker-controlled pages. The users_groups_id parameter accepts small sequential integers (typically 1–3) that are trivially enumerable, lowering the attack complexity further (GHSA Advisory, GitHub Advisory).

Impact

Successful exploitation allows a low-privileged attacker to silently escalate their user group to near-admin access, gaining permissions including full video management (PERMISSION_FULLACCESSVIDEOS), user management, upload, and livestream capabilities. Because the attack targets a group rather than an individual account, all users in the targeted group receive the escalated permissions simultaneously. No JavaScript is required — the attack fires via <img> tags alone, bypassing Content Security Policy restrictions and functioning in email clients or forum BBCode contexts where scripts are blocked (GHSA Advisory).

Exploitability

A detailed proof-of-concept (PoC) is publicly available in the GitHub Security Advisory, providing step-by-step reproduction instructions with specific URLs, parameters, and HTML payloads (GHSA Advisory). The EPSS score is approximately 0.014% (0.041% per GitHub Advisory), indicating low current exploitation probability. No in-the-wild exploitation or threat actor attribution has been reported as of publication. The vulnerability is not listed in the CISA KEV catalog. The attack requires only that an authenticated admin visit a crafted page — no privileges are required of the attacker (GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify AVideo instances running version ≤ 26.0. Register a low-privileged account and note the attacker's user group ID (typically a small integer like 2).
  2. Craft malicious page: Create an HTML page containing multiple <img> tags whose src attributes point to the target AVideo instance's plugin/Permissions/setPermission.json.php endpoint with GET parameters granting desired permissions, e.g.:
<img src="https://target-avideo.example.com/plugin/Permissions/setPermission.json.php?users_groups_id=2&plugins_id=1&type=10&isEnabled=1" style="display:none">
<img src="https://target-avideo.example.com/plugin/Permissions/setPermission.json.php?users_groups_id=2&plugins_id=1&type=5&isEnabled=1" style="display:none">
  1. Social engineering: Send the link to the malicious page to an AVideo administrator via email, forum post, embedded content, or other social engineering vector.
  2. Automatic exploitation: When the admin loads the page, the browser automatically fires GET requests to the AVideo endpoint, including the admin's SameSite=None session cookie. The User::isAdmin() check passes because the request carries the admin's valid session.
  3. Permission granted: Permissions::setPermission() executes, granting the specified permissions (e.g., PERMISSION_FULLACCESSVIDEOS, user management) to the attacker's group. The server responds with {"id":"1"} for each successful grant.
  4. Verify escalation: The attacker logs into their low-privileged account and confirms they now have near-admin capabilities including full video management, user management, upload, and livestream access (GHSA Advisory).

Indicators of compromise

  • Network: Unexpected GET requests to /plugin/Permissions/setPermission.json.php originating from external or unusual IP addresses; multiple rapid sequential requests to this endpoint with different type parameter values from the same source.
  • Logs: Web server access logs showing GET requests to setPermission.json.php with parameters users_groups_id, plugins_id, type, and isEnabled from IP addresses not associated with the AVideo admin panel; JSON responses of {"id":"1"} returned for these requests.
  • Application: Unexpected changes to user group permissions in the AVideo permissions table, particularly for non-admin groups gaining elevated permissions (e.g., type=10 for full video access, user management, upload, or livestream); permission changes occurring at unusual times or without corresponding admin activity in audit logs.
  • User Behavior: Low-privileged user accounts suddenly able to perform administrative actions such as managing videos, users, or livestreams without a corresponding admin-initiated permission change (GHSA Advisory).

Mitigation and workarounds

No patched version of WWBN AVideo is available as of the time of publication (GitHub Advisory). The recommended fix is to modify plugin/Permissions/setPermission.json.php to: (1) reject non-POST requests, (2) add isGlobalTokenValid() CSRF token validation, and (3) replace all $_REQUEST references with $_POST. Additionally, setting session.cookie_samesite to Strict or Lax in objects/include_config.php would prevent cross-site cookie submission, though this may break cross-origin iframe embedding functionality. As interim mitigations, administrators should restrict access to the AVideo admin panel to trusted networks only, monitor permission change logs for anomalies, and educate administrators to avoid clicking unsolicited links (GHSA Advisory).

Community reactions

The vulnerability was noted on social media platforms including Mastodon and Bluesky shortly after disclosure, with automated CVE tracking accounts sharing the advisory. A technical write-up was published on Dev.to covering the GET-based CSRF privilege escalation mechanics. No significant vendor statement beyond the advisory itself, nor notable independent researcher commentary, has been identified (GitHub Advisory).

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management