
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33759 is an unauthenticated Insecure Direct Object Reference (IDOR) vulnerability in WWBN AVideo affecting all versions up to and including 26.0. The flaw exists in the objects/playlistsVideos.json.php endpoint, which returns full video contents of any playlist by ID without authentication or authorization checks, exposing private and unlisted playlists to unauthenticated attackers. It was published by DanielnetoDotCom on March 24, 2026, and added to the GitHub Advisory Database on March 26, 2026. The vulnerability carries a CVSS v3.1 base score of 5.3 (Medium) (GitHub Advisory).
The root cause is a missing authorization check (CWE-862) combined with an authorization bypass through a user-controlled key (CWE-639) in objects/playlistsVideos.json.php. The endpoint accepts a playlists_id parameter and directly invokes PlayList::getVideosFromPlaylist() without any ownership or visibility validation, while the listing endpoint playlistsFromUser.json.php correctly enforces visibility controls. Because playlist IDs are sequential integers, an unauthenticated attacker can trivially enumerate all playlists — including watch_later, favorite, and custom private types — by incrementing the playlists_id parameter. The underlying SQL query in objects/playlist.php joins playlists_has_videos, videos, and users tables with no authorization filter, returning full video metadata for any requested playlist ID (GitHub Advisory, Patch Commit).
Successful exploitation allows an unauthenticated remote attacker to enumerate all users' watch histories, favorites, and private or unlisted custom playlists that were intentionally hidden from public view. Exposed data includes video titles, filenames, direct URLs, user account information, comments, and subscriber counts associated with videos in private playlists. This constitutes a significant privacy violation, revealing user viewing habits and content preferences at scale, with no integrity or availability impact (GitHub Advisory).
A public proof-of-concept (PoC) exploit consisting of concrete curl commands and a bash enumeration loop is available in the GitHub security advisory, making exploitation straightforward with no authentication required (GitHub Advisory). There is no current evidence of in-the-wild exploitation or threat actor attribution. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.042% (0.000420), placing it in the 22nd percentile for exploitation probability within 30 days (GitHub Advisory).
curl -s "http://TARGET/objects/playlistsVideos.json.php?playlists_id=1" | python3 -m json.toolA successful response returns full video metadata (titles, filenames, URLs, user info, comments) for playlist ID 1.watch_later and favorite types:for i in $(seq 1 50); do
result=$(curl -s "http://TARGET/objects/playlistsVideos.json.php?playlists_id=$i")
count=$(echo "$result" | python3 -c "import sys,json; print(len(json.load(sys.stdin)))" 2>/dev/null)
if [ "$count" != "0" ] && [ -n "$count" ]; then
echo "Playlist $i: $count videos"
fi
doneplaylistsFromUser.json.php hides private playlists while the videos endpoint exposes their contents, confirming the authorization bypass./objects/playlistsVideos.json.php with sequentially incrementing playlists_id values (e.g., ?playlists_id=1, ?playlists_id=2, ...) from a single or small set of IP addresses; similar patterns targeting the clean URL /playListsVideos.json.playlistsVideos.json.php or playListsVideos.json without any session cookie or authentication header; absence of corresponding requests to playlistsFromUser.json.php (indicating targeted enumeration rather than normal browsing).The fix is available in commit bb716fbece656c9fe39784f11e4e822b5867f1ca, which adds a PlayList::canSee() authorization check to objects/playlistsVideos.json.php before returning playlist contents, and corrects a variable name bug ($playListCanSe → $playListCanSee) in objects/playlist.php that previously caused the visibility check to malfunction (Patch Commit). Administrators should update AVideo to a version incorporating this commit immediately. As a temporary workaround, restrict access to objects/playlistsVideos.json.php via web server configuration (e.g., require authentication at the server level), and consider migrating playlist IDs to non-sequential, opaque identifiers to prevent bulk enumeration (GitHub Advisory).
The vulnerability was reported by a researcher identified as "offset" and published by DanielnetoDotCom (the AVideo maintainer) on March 24, 2026. Coverage appeared on aggregator sites including VulDB, cvefeed.io, radar.offseq.com, and a dedicated write-up at infinitsec.net shortly after disclosure. No significant vendor statements beyond the advisory itself or notable social media debate have been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."