
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-34395 is a missing authorization vulnerability in WWBN AVideo's YPTWallet plugin that allows any authenticated user to dump the complete platform user database, including personally identifiable information (PII) and wallet balances. It affects WWBN AVideo versions 26.0 and prior (composer package wwbn/avideo). The vulnerability was published on March 27, 2026, and disclosed to the GitHub Advisory Database on March 31, 2026. It carries a CVSS v3.1 base score of 6.5 (Medium) (GitHub Advisory, AVideo Advisory).
The root cause is CWE-862 (Missing Authorization): the endpoint plugin/YPTWallet/view/users.json.php only verifies that a user is logged in via User::isLogged() but omits the administrative privilege check User::isAdmin() used by all sibling endpoints in the same directory (saveBalance.php, adminManageWallets.php, pendingRequests.json.php). The underlying SQL query in YPTWallet::getAllUsers() performs a full join of the users and wallet tables (SELECT w.*, u.* ... FROM users u LEFT JOIN wallet w ON u.id = w.users_id WHERE 1=1), returning all user records. The cleanUpRowFromDatabase() function only strips fields matching /pass/i (passwords), leaving all other sensitive fields — email, phone, address, zip_code, country, region, city, first_name, last_name, birth_date, isAdmin, analyticsCode, donationLink, and balance — fully exposed. Exploitation requires only a valid (non-admin) account and a single authenticated HTTP POST request (AVideo Advisory).
Any registered user can extract the complete user database, constituting a mass data breach of PII (emails, phone numbers, physical addresses, birth dates, real names) and financial data (wallet balances) for every platform user, including administrators. The exposure of the isAdmin field also allows attackers to identify privileged accounts for targeted follow-on attacks. This breach may trigger mandatory notification obligations under GDPR or CCPA, and the disclosure of admin account identifiers could facilitate further compromise of the platform (AVideo Advisory, GitHub Advisory).
A public proof-of-concept Python exploit is available in the GitHub security advisory, demonstrating authenticated login followed by a POST request to the vulnerable endpoint to retrieve all user PII and wallet data (AVideo Advisory). The EPSS score is approximately 0.016% (4th percentile), indicating a currently low but non-zero probability of exploitation in the wild. There is no evidence of active in-the-wild exploitation or threat actor attribution at this time, and the vulnerability is not listed in the CISA KEV catalog (GitHub Advisory).
/objects/login.json.php with valid user and pass parameters to establish an authenticated session./plugin/YPTWallet/view/users.json.php with pagination parameters (e.g., current=1&rowCount=10). Iterate current to paginate through all users.isAdmin flag identifying privileged accounts (AVideo Advisory)./plugin/YPTWallet/view/users.json.php from non-administrative user sessions; sequential pagination requests (incrementing current parameter) to this endpoint from a single IP or session./plugin/YPTWallet/view/users.json.php by accounts that are not administrators; large JSON responses returned from this endpoint to regular user sessions.No official patched version was available at the time of publication; the advisory notes all versions ≤ 26.0 are affected with no patched release listed (GitHub Advisory). The recommended code fix is to replace User::isLogged() with User::isAdmin() at line 8 of plugin/YPTWallet/view/users.json.php, consistent with the authorization pattern used by all other endpoints in the same directory. As interim workarounds: disable or remove the YPTWallet plugin if not actively required; implement network-level or WAF rules to block unauthenticated or non-admin access to /plugin/YPTWallet/view/users.json.php; and monitor access logs for suspicious queries to this endpoint (AVideo Advisory).
The vulnerability was discovered and reported by aisafe.io and credited to researcher adrgs in the GitHub advisory (AVideo Advisory). No significant broader media coverage, vendor public statements beyond the advisory, or notable social media commentary has been identified at this time.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."