
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-34611 is a Cross-Site Request Forgery (CSRF) vulnerability in WWBN AVideo, an open source video platform, affecting versions 26.0 and prior. The flaw exists in the objects/emailAllUsers.json.php endpoint, which allows an attacker to trick an authenticated administrator into sending arbitrary HTML emails to every registered user on the platform. It was published on March 31, 2026, with the GitHub Advisory (GHSA-c4xj-x7p8-3x7q) released on April 1, 2026. The vulnerability carries a CVSS v3.1 base score of 6.5 (Medium) (GitHub Advisory, AVideo Advisory).
The root cause is a missing CSRF token validation on the objects/emailAllUsers.json.php endpoint (CWE-352). While the endpoint checks for an active admin session at line 10 (if (!User::isAdmin())), it never calls isGlobalTokenValid() or any equivalent CSRF check. Compounding the issue, AVideo configures session cookies with SameSite=None, which causes browsers to automatically include the admin's session cookie in cross-origin POST requests. The message body is taken directly from $_POST['message'] (line 41) and rendered as raw HTML via $mail->msgHTML() (line 48); when no specific email address is provided, the endpoint defaults to User::getAllUsers(), targeting every registered user without requiring the attacker to know any email addresses. Because the endpoint bypasses the ObjectYPT::save() method where Referer/Origin validation is implemented, no secondary protection is triggered (AVideo Advisory).
Successful exploitation allows an unauthenticated attacker (who can lure an admin to a malicious page) to send attacker-controlled HTML emails to every registered user on the AVideo platform. Because the emails are dispatched through the platform's configured SMTP server, they originate from the legitimate platform email address and pass SPF, DKIM, and DMARC authentication checks, making them indistinguishable from genuine platform communications. This enables mass phishing campaigns, credential harvesting via attacker-controlled login pages, malware distribution through HTML email payloads, and significant reputational damage to the platform operator — all without requiring knowledge of any user email addresses (AVideo Advisory, GitHub Advisory).
A proof-of-concept (PoC) exploit is publicly available in the GitHub Security Advisory, including a complete auto-submitting HTML form and a curl command that can be executed against a live AVideo instance (AVideo Advisory). The attack requires only that an authenticated administrator visits an attacker-controlled page — a single user interaction. There is no evidence of in-the-wild exploitation at this time, and no threat actor attribution has been reported. The EPSS score is approximately 0.014% (1st percentile), indicating a currently low probability of active exploitation (GitHub Advisory). The vulnerability is not listed in the CISA KEV catalog.
https://target-avideo-instance.com/objects/emailAllUsers.json.php with attacker-defined subject and message (HTML) parameters.message field with convincing HTML content (e.g., an account verification notice with a link to an attacker-controlled credential-harvesting page).SameSite=None is set on session cookies, the admin's PHPSESSID cookie is included automatically./objects/emailAllUsers.json.php from browser sessions; outbound SMTP traffic volume spike from the AVideo server following an admin login event.objects/emailAllUsers.json.php with a Referer header pointing to an external or unknown domain; SMTP server logs showing a sudden bulk email send event to all registered users.No official patched version of AVideo was available at the time of advisory publication (all versions ≤ 26.0 are affected). The recommended fix is to add CSRF token validation immediately after the admin check in objects/emailAllUsers.json.php using isGlobalTokenValid(). As interim mitigations, administrators should reconfigure session cookies to use SameSite=Strict or SameSite=Lax instead of SameSite=None, implement an approval workflow or secondary confirmation for bulk email operations, and educate administrators about the risk of visiting untrusted websites while authenticated. Monitor the AVideo GitHub repository for patch releases (AVideo Advisory, GitHub Advisory).
The vulnerability was discovered and reported by aisafe.io (finder: aisafe-bot; reporter: adrgs) and published by the AVideo maintainer DanielnetoDotCom on March 30, 2026. The advisory was noted in automated CVE tracking feeds and Bluesky CVE notification accounts shortly after publication. No significant broader media coverage or notable researcher commentary beyond the advisory itself has been identified (AVideo Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."