
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33649 is a GET-based Cross-Site Request Forgery (CSRF) vulnerability in WWBN AVideo, an open source video platform, that enables privilege escalation via arbitrary permission modification. The vulnerability affects all versions up to and including 26.0 (the GitHub advisory notes ≤ 27.0 for the repository advisory). It was published on March 22–23, 2026, with no patched version available as of publication. The CVSS v3.1 base score is 8.1 (High) per the GitHub Advisory Database, or 8.8 (High) per NVD scoring (GitHub Advisory, GHSA Advisory).
The vulnerability (CWE-352) stems from three compounding weaknesses in AVideo's codebase. First, plugin/Permissions/setPermission.json.php uses PHP's $_REQUEST superglobal instead of $_POST, meaning it accepts GET parameters for a state-changing operation. Second, the endpoint performs only an User::isAdmin() check and omits the isGlobalTokenValid() CSRF token validation that other state-mutating endpoints (e.g., saveSort.json.php, pluginImport.json.php) enforce. Third, objects/include_config.php explicitly sets session.cookie_samesite=None to support cross-origin iframe embedding, which causes the admin's session cookie to be sent on cross-origin requests — including those triggered by <img> tags on attacker-controlled pages. The users_groups_id parameter accepts small sequential integers (typically 1–3) that are trivially enumerable, lowering the attack complexity further (GHSA Advisory, GitHub Advisory).
Successful exploitation allows a low-privileged attacker to silently escalate their user group to near-admin access, gaining permissions including full video management (PERMISSION_FULLACCESSVIDEOS), user management, upload, and livestream capabilities. Because the attack targets a group rather than an individual account, all users in the targeted group receive the escalated permissions simultaneously. No JavaScript is required — the attack fires via <img> tags alone, bypassing Content Security Policy restrictions and functioning in email clients or forum BBCode contexts where scripts are blocked (GHSA Advisory).
A detailed proof-of-concept (PoC) is publicly available in the GitHub Security Advisory, providing step-by-step reproduction instructions with specific URLs, parameters, and HTML payloads (GHSA Advisory). The EPSS score is approximately 0.014% (0.041% per GitHub Advisory), indicating low current exploitation probability. No in-the-wild exploitation or threat actor attribution has been reported as of publication. The vulnerability is not listed in the CISA KEV catalog. The attack requires only that an authenticated admin visit a crafted page — no privileges are required of the attacker (GitHub Advisory).
<img> tags whose src attributes point to the target AVideo instance's plugin/Permissions/setPermission.json.php endpoint with GET parameters granting desired permissions, e.g.:<img src="https://target-avideo.example.com/plugin/Permissions/setPermission.json.php?users_groups_id=2&plugins_id=1&type=10&isEnabled=1" style="display:none">
<img src="https://target-avideo.example.com/plugin/Permissions/setPermission.json.php?users_groups_id=2&plugins_id=1&type=5&isEnabled=1" style="display:none">SameSite=None session cookie. The User::isAdmin() check passes because the request carries the admin's valid session.Permissions::setPermission() executes, granting the specified permissions (e.g., PERMISSION_FULLACCESSVIDEOS, user management) to the attacker's group. The server responds with {"id":"1"} for each successful grant./plugin/Permissions/setPermission.json.php originating from external or unusual IP addresses; multiple rapid sequential requests to this endpoint with different type parameter values from the same source.setPermission.json.php with parameters users_groups_id, plugins_id, type, and isEnabled from IP addresses not associated with the AVideo admin panel; JSON responses of {"id":"1"} returned for these requests.type=10 for full video access, user management, upload, or livestream); permission changes occurring at unusual times or without corresponding admin activity in audit logs.No patched version of WWBN AVideo is available as of the time of publication (GitHub Advisory). The recommended fix is to modify plugin/Permissions/setPermission.json.php to: (1) reject non-POST requests, (2) add isGlobalTokenValid() CSRF token validation, and (3) replace all $_REQUEST references with $_POST. Additionally, setting session.cookie_samesite to Strict or Lax in objects/include_config.php would prevent cross-site cookie submission, though this may break cross-origin iframe embedding functionality. As interim mitigations, administrators should restrict access to the AVideo admin panel to trusted networks only, monitor permission change logs for anomalies, and educate administrators to avoid clicking unsolicited links (GHSA Advisory).
The vulnerability was noted on social media platforms including Mastodon and Bluesky shortly after disclosure, with automated CVE tracking accounts sharing the advisory. A technical write-up was published on Dev.to covering the GET-based CSRF privilege escalation mechanics. No significant vendor statement beyond the advisory itself, nor notable independent researcher commentary, has been identified (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."