
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-34738 is an improper authorization vulnerability in WWBN AVideo, an open source video platform, that allows any authenticated uploader to bypass admin-controlled content moderation workflows by manipulating the overrideStatus request parameter. Discovered by aisafe.io and published on March 30–31, 2026, it affects AVideo versions 26.0 and prior. The vulnerability carries a CVSS v3.1 base score of 4.3 (Medium) (GitHub Advisory, GHSA).
The root cause is CWE-285 (Improper Authorization): at objects/video.php lines 1055–1056, the application reads the overrideStatus parameter directly from the HTTP request and passes it to setStatus() without any permission check — if (!empty($_REQUEST['overrideStatus'])) { return $this->setStatus($_REQUEST['overrideStatus']); }. The setStatus() method validates the value against a list of recognized status codes (a, k, i, u, x, etc.) but never verifies whether the calling user is authorized to apply that status. This code path is reachable from two endpoints: objects/videoAddNew.json.php (line 157, new video uploads) and objects/aVideoEncoder.json.php (line 114, encoded video processing). Exploitation requires only a valid authenticated session with upload permissions and a single additional form field (GHSA).
Any authenticated user with upload permissions can immediately publish videos to active/public status, bypassing the platform's moderation queue and draft workflow. This undermines content policy enforcement, including legal compliance obligations such as DMCA takedowns and age-gated content controls, which could carry regulatory consequences for platform operators. Attackers can also set arbitrary statuses (e.g., unlisted, inactive) on their own videos, circumventing platform-level restrictions on those features. Confidentiality and availability are not directly impacted; the primary risk is to content integrity and platform governance (GHSA).
A proof-of-concept exploit is publicly available in the GitHub Security Advisory, consisting of concrete curl commands targeting the live upload endpoint with the overrideStatus=a parameter. The EPSS score is approximately 0.011% (2nd percentile), indicating low current exploitation probability. There is no evidence of in-the-wild exploitation at this time, no known threat actor attribution, and the vulnerability is not listed in the CISA KEV catalog (GitHub Advisory, GHSA).
k) by uploading a test video without the override parameter and observing it enters a review queue.PHPSESSID), send a POST request to objects/videoAddNew.json.php with the overrideStatus=a form field included:curl -b "PHPSESSID=USER_SESSION" \
-X POST "https://your-avideo-instance.com/objects/videoAddNew.json.php" \
-F "title=Bypassed Moderation" \
-F "description=This video skips the review queue" \
-F "videoLink=https://example.com/video.mp4" \
-F "overrideStatus=a"curl -s "https://your-avideo-instance.com/video/VIDEO_CLEAN_TITLE" | grep -o ".*"overrideStatus=u for unlisted) to bypass platform-level restrictions on those features (GHSA)./objects/videoAddNew.json.php or /objects/aVideoEncoder.json.php containing the form field overrideStatus with values such as a, u, or other status codes from non-administrative user sessions.overrideStatus in the request body; application logs showing videos transitioning directly to active status without passing through the moderation queue.unlisted or inactive status changes on videos owned by regular uploaders (GHSA).As of the time of advisory publication, no patched version of AVideo is available for this vulnerability. The recommended fix is to add an authorization check in objects/video.php at line 1055 before applying the overrideStatus parameter, restricting its use to administrators or users with explicit video management permissions:
if (!empty($_REQUEST['overrideStatus']) && (User::isAdmin() || Permissions::canAdminVideos())) {
return $this->setStatus($_REQUEST['overrideStatus']);
}As a workaround, administrators should consider disabling public upload permissions for untrusted users, implementing a web application firewall (WAF) rule to strip or block the overrideStatus parameter from POST requests to the affected endpoints, and monitoring upload activity for unexpected status transitions (GHSA).
The vulnerability was discovered and reported by aisafe.io and credited to researcher adrgs. The advisory was published by the AVideo project maintainer DanielnetoDotCom on March 30, 2026. No significant broader media coverage or notable community commentary beyond the GitHub advisory has been identified at this time (GHSA).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."