CVE-2026-34247: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-34247 is an Insecure Direct Object Reference (IDOR) / Missing Authorization vulnerability in WWBN AVideo, an open source video platform. It affects all versions up to and including 26.0, where the plugin/Live/uploadPoster.php endpoint allows any authenticated user to overwrite the poster image for any scheduled live stream by supplying an arbitrary live_schedule_id. The vulnerability was published on March 27, 2026, with a fix committed the same day. It carries a CVSS v3.1 base score of 5.4 (Medium) (GitHub Advisory, Github Advisory).

Technical details

The root cause is CWE-862 (Missing Authorization): the plugin/Live/uploadPoster.php endpoint accepts a user-controlled live_schedule_id parameter from $_REQUEST and only validates that the requesting user is logged in via User::isLogged(), without verifying that the authenticated user owns the targeted live schedule. The Live_schedule::getPosterPaths() static method constructs file paths purely from the numeric ID, and after overwriting the poster file via move_uploaded_file(), the endpoint calls Live::notifySocketStats("socketLiveOFFCallback", $array) which broadcasts the victim's broadcast key and users_id to all connected WebSocket clients via sendSocketMessageToAll(). Notably, parallel endpoints (uploadPoster.json.php and view/Live_schedule/uploadPoster.php) do implement ownership checks, confirming this omission is an oversight. Schedule IDs are sequential integers, making enumeration trivial (GitHub Advisory).

Impact

Successful exploitation allows any authenticated user to tamper with content by overwriting poster images on any other user's scheduled live stream, enabling defacement or phishing attacks (e.g., replacing a legitimate poster with a malicious redirect image). The socketLiveOFFCallback broadcast triggered after each exploit leaks the victim's broadcast key and users_id to all connected WebSocket clients, constituting an information disclosure risk. Additionally, the false offline notification misleads all connected viewers into believing the victim's stream has gone offline, disrupting the victim's audience and platform integrity (GitHub Advisory).

Exploitability

A proof-of-concept (PoC) exploit is publicly available in the GitHub Security Advisory, consisting of concrete curl commands that demonstrate the full attack chain against a real AVideo deployment. The EPSS score is approximately 0.013% (2nd percentile), indicating low current exploitation probability. There is no evidence of in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The vulnerability requires only a low-privilege authenticated account and no user interaction, lowering the barrier for exploitation (Github Advisory, GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify an AVideo instance running version 26.0 or earlier. Enumerate scheduled live streams by probing sequential live_schedule_id integers (e.g., 1, 2, 3, ...) to identify valid targets.
  2. Authentication: Register or obtain credentials for any low-privilege user account on the target AVideo instance. Log in to obtain a session cookie:
    curl -c cookies.txt -X POST 'https://target.com/objects/login.json.php' \
      -d 'user=attacker@example.com&pass=attackerpassword'
  3. Overwrite victim's poster: Send a multipart POST request to the vulnerable endpoint with an arbitrary live_schedule_id belonging to another user:
    curl -b cookies.txt \
      -F 'file_data=@malicious.jpg' \
      -F 'live_schedule_id=1' \
      -F 'live_servers_id=0' \
      'https://target.com/plugin/Live/uploadPoster.php'
  4. Observe information disclosure: The server responds with success ({}) and broadcasts a socketLiveOFFCallback WebSocket message to all connected clients containing the victim's broadcast key and users_id.
  5. Verify tampering: Confirm the poster was replaced by fetching the poster image URL:
    curl -o - 'https://target.com/videos/live_schedule_posters/schedule_1.jpg' | file -
  6. Scale attack: Iterate over sequential schedule IDs to target all scheduled live streams on the platform (GitHub Advisory).

Indicators of compromise

  • Network: Unusual multipart POST requests to /plugin/Live/uploadPoster.php from users who do not own the targeted live_schedule_id; repeated requests to the same endpoint with incrementing live_schedule_id values (enumeration pattern).
  • Logs: Web server access logs showing POST requests to /plugin/Live/uploadPoster.php with live_schedule_id values not associated with the authenticated user's account; multiple rapid requests from a single session targeting different schedule IDs.
  • WebSocket Traffic: Unexpected socketLiveOFFCallback messages broadcast to WebSocket clients containing broadcast key and users_id fields at unusual times (e.g., when the stream owner is not actively managing their stream).
  • File System: Unexpected modification timestamps on files under videos/live_schedule_posters/ (e.g., schedule_<id>.jpg) that do not correspond to actions by the schedule owner; replacement of legitimate poster images with unrecognized content (GitHub Advisory).

Mitigation and workarounds

The fix is available in commit 5fcb3bdf59f26d65e203cfbc8a685356ba300b60, which adds an ownership check in plugin/Live/uploadPoster.php immediately after the login verification — rejecting requests where the authenticated user is neither an admin nor the owner of the targeted schedule. Administrators should upgrade to a version of AVideo that includes this commit (post-26.0). As a temporary workaround, restrict access to the /plugin/Live/uploadPoster.php endpoint via web server configuration (e.g., require additional authentication or block external access) until the patch can be applied. Additionally, audit existing live stream poster images to verify they have not been tampered with (Patch Commit, GitHub Advisory).

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management