CVE-2026-34395: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-34395 is a missing authorization vulnerability in WWBN AVideo's YPTWallet plugin that allows any authenticated user to dump the complete platform user database, including personally identifiable information (PII) and wallet balances. It affects WWBN AVideo versions 26.0 and prior (composer package wwbn/avideo). The vulnerability was published on March 27, 2026, and disclosed to the GitHub Advisory Database on March 31, 2026. It carries a CVSS v3.1 base score of 6.5 (Medium) (GitHub Advisory, AVideo Advisory).

Technical details

The root cause is CWE-862 (Missing Authorization): the endpoint plugin/YPTWallet/view/users.json.php only verifies that a user is logged in via User::isLogged() but omits the administrative privilege check User::isAdmin() used by all sibling endpoints in the same directory (saveBalance.php, adminManageWallets.php, pendingRequests.json.php). The underlying SQL query in YPTWallet::getAllUsers() performs a full join of the users and wallet tables (SELECT w.*, u.* ... FROM users u LEFT JOIN wallet w ON u.id = w.users_id WHERE 1=1), returning all user records. The cleanUpRowFromDatabase() function only strips fields matching /pass/i (passwords), leaving all other sensitive fields — email, phone, address, zip_code, country, region, city, first_name, last_name, birth_date, isAdmin, analyticsCode, donationLink, and balance — fully exposed. Exploitation requires only a valid (non-admin) account and a single authenticated HTTP POST request (AVideo Advisory).

Impact

Any registered user can extract the complete user database, constituting a mass data breach of PII (emails, phone numbers, physical addresses, birth dates, real names) and financial data (wallet balances) for every platform user, including administrators. The exposure of the isAdmin field also allows attackers to identify privileged accounts for targeted follow-on attacks. This breach may trigger mandatory notification obligations under GDPR or CCPA, and the disclosure of admin account identifiers could facilitate further compromise of the platform (AVideo Advisory, GitHub Advisory).

Exploitability

A public proof-of-concept Python exploit is available in the GitHub security advisory, demonstrating authenticated login followed by a POST request to the vulnerable endpoint to retrieve all user PII and wallet data (AVideo Advisory). The EPSS score is approximately 0.016% (4th percentile), indicating a currently low but non-zero probability of exploitation in the wild. There is no evidence of active in-the-wild exploitation or threat actor attribution at this time, and the vulnerability is not listed in the CISA KEV catalog (GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify publicly accessible WWBN AVideo instances running version 26.0 or earlier using search engines (e.g., Shodan, Censys) or by checking the platform's version disclosure.
  2. Register or obtain credentials: Create a regular (non-admin) user account on the target AVideo instance, or use any existing low-privilege credentials.
  3. Authenticate: Send an HTTP POST request to /objects/login.json.php with valid user and pass parameters to establish an authenticated session.
  4. Request the vulnerable endpoint: Send an authenticated HTTP POST request to /plugin/YPTWallet/view/users.json.php with pagination parameters (e.g., current=1&rowCount=10). Iterate current to paginate through all users.
  5. Extract user data: Parse the JSON response, which contains all platform users' PII (email, phone, address, zip_code, country, region, city, first_name, last_name, birth_date) and financial data (wallet balance), as well as the isAdmin flag identifying privileged accounts (AVideo Advisory).

Indicators of compromise

  • Network: Repeated or automated HTTP POST requests to /plugin/YPTWallet/view/users.json.php from non-administrative user sessions; sequential pagination requests (incrementing current parameter) to this endpoint from a single IP or session.
  • Logs: Web server access logs showing POST requests to /plugin/YPTWallet/view/users.json.php by accounts that are not administrators; large JSON responses returned from this endpoint to regular user sessions.
  • Behavioral: A single user session making many rapid requests to the wallet users endpoint in a short time window, consistent with automated scraping of the full user database (AVideo Advisory).

Mitigation and workarounds

No official patched version was available at the time of publication; the advisory notes all versions ≤ 26.0 are affected with no patched release listed (GitHub Advisory). The recommended code fix is to replace User::isLogged() with User::isAdmin() at line 8 of plugin/YPTWallet/view/users.json.php, consistent with the authorization pattern used by all other endpoints in the same directory. As interim workarounds: disable or remove the YPTWallet plugin if not actively required; implement network-level or WAF rules to block unauthenticated or non-admin access to /plugin/YPTWallet/view/users.json.php; and monitor access logs for suspicious queries to this endpoint (AVideo Advisory).

Community reactions

The vulnerability was discovered and reported by aisafe.io and credited to researcher adrgs in the GitHub advisory (AVideo Advisory). No significant broader media coverage, vendor public statements beyond the advisory, or notable social media commentary has been identified at this time.

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management