
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33688 is a pre-captcha user enumeration and account status disclosure vulnerability in WWBN AVideo, an open source video platform. The flaw exists in the password recovery endpoint (objects/userRecoverPass.php), which performs user existence and account status checks before validating the captcha, enabling unauthenticated attackers to enumerate valid usernames and determine account status at scale. All versions up to and including 26.0 are affected. The vulnerability was published on March 23, 2026, and carries a CVSS v3.1 base score of 5.3 (Medium) (Github Advisory, GHSA Advisory).
The root cause is an Observable Response Discrepancy (CWE-204) in objects/userRecoverPass.php. The vulnerable code instantiates a User object from the unsanitized $_REQUEST['user'] parameter at line 11, then returns three distinct JSON error responses — "User not found", "The user is not active", or "Captcha is empty" — before any captcha validation occurs (lines 27–41). This ordering creates a reliable oracle: a "Captcha is empty" response confirms the user exists and is active, while the earlier errors reveal non-existence or inactive/banned status. No rate limiting (rateLimitByIP) or brute-force protection (bruteForceBlock) is applied to the endpoint, and the session-based DDoS protection is trivially bypassed by omitting cookies. A public PoC including curl commands and a bulk enumeration bash script is included in the security advisory (GHSA Advisory).
Successful exploitation allows unauthenticated remote attackers to enumerate valid usernames and determine whether accounts are active, inactive, or banned — without solving any captcha. The confirmed username list can then be leveraged for targeted credential stuffing or brute-force attacks against the login endpoint, phishing campaigns against real users, or social engineering. There is no direct integrity or availability impact, but the confidentiality exposure facilitates further attacks that could lead to account compromise (GHSA Advisory).
A public proof-of-concept exploit is available in the GitHub security advisory, consisting of curl commands and a bash script that automate bulk user enumeration without requiring captcha solving (GHSA Advisory). There is no evidence of in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The EPSS score is approximately 0.086% (0.000290 per Feedly), placing it in the 25th percentile for exploitation probability within 30 days (Github Advisory).
/AVideo/objects/userRecoverPass.php with a candidate username and an empty captcha field:curl -s -X POST 'http://target/AVideo/objects/userRecoverPass.php' -d 'user=admin&captcha=' | jq .error"User not found" → username does not exist"The user is not active" → username exists but account is inactive or banned"Captcha is empty" → username exists and account is activefor user in admin root test user1 user2 moderator editor; do
result=$(curl -s -X POST 'http://target/AVideo/objects/userRecoverPass.php' -d "user=${user}&captcha=")
error=$(echo "$result" | jq -r .error)
if [ "$error" = "Captcha is empty" ]; then echo "[ACTIVE] $user"
elif [ "$error" = "The user is not active" ]; then echo "[INACTIVE] $user"
else echo "[NOT FOUND] $user"; fi
done/AVideo/objects/userRecoverPass.php from a single IP or rotating IPs; requests with empty or missing captcha parameter values; absence of session cookies in repeated requests to this endpoint.userRecoverPass.php with varying user parameter values; AVideo application logs (_error_log) showing repeated RecoverPass start entries from the same IP with different usernames.The fix is available in commit e42f54123b460fd1b2ee01f2ce3d4a386e88d157, which reorders the logic in objects/userRecoverPass.php to validate the captcha before performing any user existence checks, and returns a generic success message regardless of account status to prevent enumeration (Patch Commit). Administrators should update AVideo to a version newer than 26.0 that includes this patch. As additional defense-in-depth, the advisory recommends adding rateLimitByIP() to the password recovery endpoint and ensuring all sensitive endpoints return generic responses that do not reveal internal account state (GHSA Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."