CVE-2026-34362: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-34362 is an Insufficient Session Expiration vulnerability in WWBN AVideo, an open source video platform, where WebSocket tokens never expire due to commented-out timeout validation code. Affecting all versions up to and including 26.0, the flaw allows captured or legitimately obtained tokens to provide permanent WebSocket access — even after the originating user account is deleted, banned, or demoted from admin. It was published on March 27, 2026, with a patch commit available shortly after. The vulnerability carries a CVSS v3.1 base score of 5.4 (Medium) (Github Advisory, Feedly).

Technical details

The root cause is CWE-613 (Insufficient Session Expiration): the verifyTokenSocket() function in plugin/YPTSocket/functions.php has its timeout enforcement (return false) commented out at lines 77–80, so the expiry check evaluates but never acts on failure, always returning true. WebSocket tokens are generated with a 12-hour expiration via getToken(43200) and contain security-critical claims including isAdmin, from_users_id, user_name, IP, browser, and device ID — but the WebSocket-specific path never enforces the timeout, unlike the regular HTTP path in objects/functions.php. An attacker with any valid (or previously valid) token can connect to the WebSocket endpoint at ws://target.com:8888/?webSocketToken=TOKEN indefinitely, and the webSocketToken message type also allows anonymous connections to upgrade their identity using a stolen token (Github Advisory, AVideo Security Advisory).

Impact

Exploitation allows permanent unauthorized WebSocket access regardless of account status changes — deleted, banned, or demoted users retain their original identity and privilege level. Admin-level tokens expose real-time data for all connected users, including IP addresses, geographic locations (if the User_location plugin is enabled), current page URLs (selfURI), browser fingerprints, and device IDs, enabling real-time surveillance of platform users. Additionally, stolen tokens can be used to impersonate other users in chat and messaging via identity hijacking, and any secondary vulnerability (e.g., XSS or log exposure) that leaks a token now provides permanent rather than time-limited access, significantly amplifying the impact of token theft (AVideo Security Advisory).

Exploitability

A detailed proof-of-concept (PoC) is publicly available in the GitHub security advisory, including step-by-step curl and wscat commands demonstrating token capture and reuse against a live AVideo deployment (AVideo Security Advisory). Exploitation requires low privileges (any authenticated user can obtain a token) and no user interaction, making it accessible to a broad attacker population. The EPSS score is approximately 0.013% (2nd percentile), and there is no evidence of in-the-wild exploitation or CISA KEV catalog listing at this time (Github Advisory).

Exploitation steps

  1. Reconnaissance: Identify an AVideo instance running version ≤ 26.0 using web search, Shodan, or Censys. Confirm the WebSocket plugin is active by checking for the YPTSocket endpoint.
  2. Obtain a WebSocket token: Authenticate to the target AVideo instance and retrieve a WebSocket token using:
    curl -s -b 'PHPSESSID=VALID_SESSION' \
      'https://target.com/plugin/YPTSocket/getWebSocket.json.php' | jq -r '.webSocketToken'
    Save the output as TOKEN.
  3. Wait for token expiry (or use a previously captured token): In a real attack scenario, the attacker may already possess a token captured via XSS, log exposure, or network interception — even one older than 12 hours.
  4. Connect with the expired token: Use wscat to establish a WebSocket connection with the expired token:
    wscat -c 'ws://target.com:8888/?webSocketToken=TOKEN'
    The connection succeeds because verifyTokenSocket() skips the timeout enforcement.
  5. Receive broadcast data: Once connected, the server sends periodic getTotals broadcasts. If the token carries isAdmin=true, these broadcasts include all connected users' selfURI, IP addresses, browser fingerprints, device IDs, usernames, and locations.
  6. Enumerate connected users (non-admin): Even without admin privileges, send the following JSON message to list connected users:
    {"msg":"getClientsList","webSocketToken":"TOKEN"}
    The response includes users_id, isAdmin status, and usernames for all connected clients (AVideo Security Advisory).

Indicators of compromise

  • Network: WebSocket connection requests to ws://<host>:8888/?webSocketToken=<TOKEN> from unexpected or previously revoked user accounts; repeated WebSocket connections from IPs not associated with any active user session.
  • Logs: AVideo application logs showing verifyTokenSocket calls succeeding for tokens with obj->timeout values in the past (timestamps older than 12 hours); absence of verifyToken token timout log entries despite old tokens being used (pre-patch behavior).
  • Behavior: WebSocket connections persisting from accounts that have been deleted, banned, or demoted; getClientsList messages sent from anonymous (users_id=0) or low-privilege connections; periodic receipt of full user connection data (IP, browser, location) by non-admin sessions.
  • File System: No file-system artifacts expected for this vulnerability, as exploitation is entirely network/session-based (AVideo Security Advisory).

Mitigation and workarounds

The fix is available in commit 5d5237121bf82c24e9e0fdd5bc1699f1157783c5, which uncomments the return false statement in verifyTokenSocket() at plugin/YPTSocket/functions.php:79 and updates script.js to fetch fresh tokens via startSocket() on reconnection rather than reusing stale tokens. Operators should update to any AVideo version incorporating this commit immediately. As additional hardening, the advisory recommends restricting the getClientsList handler to admin-only access, periodically re-validating the isAdmin claim against the database rather than trusting the token for the connection lifetime, implementing network-level restrictions on WebSocket port access, and monitoring for unusual WebSocket connection patterns from revoked accounts (AVideo Security Advisory, Patch Commit).

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management