
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-34362 is an Insufficient Session Expiration vulnerability in WWBN AVideo, an open source video platform, where WebSocket tokens never expire due to commented-out timeout validation code. Affecting all versions up to and including 26.0, the flaw allows captured or legitimately obtained tokens to provide permanent WebSocket access — even after the originating user account is deleted, banned, or demoted from admin. It was published on March 27, 2026, with a patch commit available shortly after. The vulnerability carries a CVSS v3.1 base score of 5.4 (Medium) (Github Advisory, Feedly).
The root cause is CWE-613 (Insufficient Session Expiration): the verifyTokenSocket() function in plugin/YPTSocket/functions.php has its timeout enforcement (return false) commented out at lines 77–80, so the expiry check evaluates but never acts on failure, always returning true. WebSocket tokens are generated with a 12-hour expiration via getToken(43200) and contain security-critical claims including isAdmin, from_users_id, user_name, IP, browser, and device ID — but the WebSocket-specific path never enforces the timeout, unlike the regular HTTP path in objects/functions.php. An attacker with any valid (or previously valid) token can connect to the WebSocket endpoint at ws://target.com:8888/?webSocketToken=TOKEN indefinitely, and the webSocketToken message type also allows anonymous connections to upgrade their identity using a stolen token (Github Advisory, AVideo Security Advisory).
Exploitation allows permanent unauthorized WebSocket access regardless of account status changes — deleted, banned, or demoted users retain their original identity and privilege level. Admin-level tokens expose real-time data for all connected users, including IP addresses, geographic locations (if the User_location plugin is enabled), current page URLs (selfURI), browser fingerprints, and device IDs, enabling real-time surveillance of platform users. Additionally, stolen tokens can be used to impersonate other users in chat and messaging via identity hijacking, and any secondary vulnerability (e.g., XSS or log exposure) that leaks a token now provides permanent rather than time-limited access, significantly amplifying the impact of token theft (AVideo Security Advisory).
A detailed proof-of-concept (PoC) is publicly available in the GitHub security advisory, including step-by-step curl and wscat commands demonstrating token capture and reuse against a live AVideo deployment (AVideo Security Advisory). Exploitation requires low privileges (any authenticated user can obtain a token) and no user interaction, making it accessible to a broad attacker population. The EPSS score is approximately 0.013% (2nd percentile), and there is no evidence of in-the-wild exploitation or CISA KEV catalog listing at this time (Github Advisory).
curl -s -b 'PHPSESSID=VALID_SESSION' \
'https://target.com/plugin/YPTSocket/getWebSocket.json.php' | jq -r '.webSocketToken'Save the output as TOKEN.wscat to establish a WebSocket connection with the expired token:wscat -c 'ws://target.com:8888/?webSocketToken=TOKEN'The connection succeeds because verifyTokenSocket() skips the timeout enforcement.getTotals broadcasts. If the token carries isAdmin=true, these broadcasts include all connected users' selfURI, IP addresses, browser fingerprints, device IDs, usernames, and locations.{"msg":"getClientsList","webSocketToken":"TOKEN"}The response includes users_id, isAdmin status, and usernames for all connected clients (AVideo Security Advisory).ws://<host>:8888/?webSocketToken=<TOKEN> from unexpected or previously revoked user accounts; repeated WebSocket connections from IPs not associated with any active user session.verifyTokenSocket calls succeeding for tokens with obj->timeout values in the past (timestamps older than 12 hours); absence of verifyToken token timout log entries despite old tokens being used (pre-patch behavior).getClientsList messages sent from anonymous (users_id=0) or low-privilege connections; periodic receipt of full user connection data (IP, browser, location) by non-admin sessions.The fix is available in commit 5d5237121bf82c24e9e0fdd5bc1699f1157783c5, which uncomments the return false statement in verifyTokenSocket() at plugin/YPTSocket/functions.php:79 and updates script.js to fetch fresh tokens via startSocket() on reconnection rather than reusing stale tokens. Operators should update to any AVideo version incorporating this commit immediately. As additional hardening, the advisory recommends restricting the getClientsList handler to admin-only access, periodically re-validating the isAdmin claim against the database rather than trusting the token for the connection lifetime, implementing network-level restrictions on WebSocket port access, and monitoring for unusual WebSocket connection patterns from revoked accounts (AVideo Security Advisory, Patch Commit).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."