CVE-2026-34738: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-34738 is an improper authorization vulnerability in WWBN AVideo, an open source video platform, that allows any authenticated uploader to bypass admin-controlled content moderation workflows by manipulating the overrideStatus request parameter. Discovered by aisafe.io and published on March 30–31, 2026, it affects AVideo versions 26.0 and prior. The vulnerability carries a CVSS v3.1 base score of 4.3 (Medium) (GitHub Advisory, GHSA).

Technical details

The root cause is CWE-285 (Improper Authorization): at objects/video.php lines 1055–1056, the application reads the overrideStatus parameter directly from the HTTP request and passes it to setStatus() without any permission check — if (!empty($_REQUEST['overrideStatus'])) { return $this->setStatus($_REQUEST['overrideStatus']); }. The setStatus() method validates the value against a list of recognized status codes (a, k, i, u, x, etc.) but never verifies whether the calling user is authorized to apply that status. This code path is reachable from two endpoints: objects/videoAddNew.json.php (line 157, new video uploads) and objects/aVideoEncoder.json.php (line 114, encoded video processing). Exploitation requires only a valid authenticated session with upload permissions and a single additional form field (GHSA).

Impact

Any authenticated user with upload permissions can immediately publish videos to active/public status, bypassing the platform's moderation queue and draft workflow. This undermines content policy enforcement, including legal compliance obligations such as DMCA takedowns and age-gated content controls, which could carry regulatory consequences for platform operators. Attackers can also set arbitrary statuses (e.g., unlisted, inactive) on their own videos, circumventing platform-level restrictions on those features. Confidentiality and availability are not directly impacted; the primary risk is to content integrity and platform governance (GHSA).

Exploitability

A proof-of-concept exploit is publicly available in the GitHub Security Advisory, consisting of concrete curl commands targeting the live upload endpoint with the overrideStatus=a parameter. The EPSS score is approximately 0.011% (2nd percentile), indicating low current exploitation probability. There is no evidence of in-the-wild exploitation at this time, no known threat actor attribution, and the vulnerability is not listed in the CISA KEV catalog (GitHub Advisory, GHSA).

Exploitation steps

  1. Obtain upload credentials: Register or obtain a regular user account on the target AVideo instance that has upload permissions — no administrative privileges are required.
  2. Confirm moderation is enabled: Verify that the platform enforces a moderation workflow (new videos default to draft/pending status k) by uploading a test video without the override parameter and observing it enters a review queue.
  3. Craft the malicious upload request: Using a valid session cookie (PHPSESSID), send a POST request to objects/videoAddNew.json.php with the overrideStatus=a form field included:
curl -b "PHPSESSID=USER_SESSION" \
  -X POST "https://your-avideo-instance.com/objects/videoAddNew.json.php" \
  -F "title=Bypassed Moderation" \
  -F "description=This video skips the review queue" \
  -F "videoLink=https://example.com/video.mp4" \
  -F "overrideStatus=a"
  1. Verify publication: Confirm the video is immediately publicly visible by accessing its URL directly:
curl -s "https://your-avideo-instance.com/video/VIDEO_CLEAN_TITLE" | grep -o ".*"
  1. Set arbitrary statuses (optional): Use the same technique with other status codes (e.g., overrideStatus=u for unlisted) to bypass platform-level restrictions on those features (GHSA).

Indicators of compromise

  • Network: HTTP POST requests to /objects/videoAddNew.json.php or /objects/aVideoEncoder.json.php containing the form field overrideStatus with values such as a, u, or other status codes from non-administrative user sessions.
  • Logs: Web server access logs showing POST requests to the above endpoints from regular user accounts (non-admin sessions) with overrideStatus in the request body; application logs showing videos transitioning directly to active status without passing through the moderation queue.
  • Application State: Videos appearing in the public-facing catalog immediately after upload by non-admin users, without any record of moderator approval in the admin review queue; unexpected unlisted or inactive status changes on videos owned by regular uploaders (GHSA).

Mitigation and workarounds

As of the time of advisory publication, no patched version of AVideo is available for this vulnerability. The recommended fix is to add an authorization check in objects/video.php at line 1055 before applying the overrideStatus parameter, restricting its use to administrators or users with explicit video management permissions:

if (!empty($_REQUEST['overrideStatus']) && (User::isAdmin() || Permissions::canAdminVideos())) {
    return $this->setStatus($_REQUEST['overrideStatus']);
}

As a workaround, administrators should consider disabling public upload permissions for untrusted users, implementing a web application firewall (WAF) rule to strip or block the overrideStatus parameter from POST requests to the affected endpoints, and monitoring upload activity for unexpected status transitions (GHSA).

Community reactions

The vulnerability was discovered and reported by aisafe.io and credited to researcher adrgs. The advisory was published by the AVideo project maintainer DanielnetoDotCom on March 30, 2026. No significant broader media coverage or notable community commentary beyond the GitHub advisory has been identified at this time (GHSA).

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management