CVE-2026-35448: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-35448 is a Missing Authorization vulnerability in the BlockonomicsYPT plugin bundled with WWBN AVideo, an open-source video platform. The check.php endpoint returns Bitcoin payment order data for any address without requiring authentication, exposing sensitive payment records to unauthenticated network attackers. All AVideo versions up to and including 26.0 are affected; no patched version has been released as of the advisory date. The vulnerability was discovered by aisafe.io, published to the GitHub Advisory Database on April 4, 2026, and assigned a CVSS v3.1 base score of 3.7 (Low) (Github Advisory, AVideo Advisory).

Technical details

The root cause is CWE-862 (Missing Authorization): the plugin/BlockonomicsYPT/check.php endpoint at lines 20–30 accepts a Bitcoin address via the addr GET parameter, queries the database for the associated order, and returns the result as JSON — all without any session or permission check. The parent page invoice.php enforces authentication, but check.php does not inherit or enforce that requirement. Because Bitcoin addresses are publicly visible on the blockchain, an attacker can enumerate platform-associated addresses by monitoring on-chain transactions and then directly query the endpoint. The vulnerable code pattern is: $addr = $_GET['addr']; $obj = $order->getFromAddressFromDb($addr); die(json_encode($obj)); (Github Advisory, AVideo Advisory).

Impact

Successful exploitation results in unauthenticated disclosure of payment order records, including the buyer's internal user ID, total payment value, currency, expected and received BTC amounts, transaction ID, payment status, and order creation timestamp. This links on-chain Bitcoin transactions to specific platform user accounts, constituting a significant privacy violation for users who made cryptocurrency payments. There is no integrity or availability impact; the vulnerability is limited to confidentiality of payment data (Github Advisory).

Exploitability

A proof-of-concept exploit is publicly available in the GitHub security advisory, consisting of a single unauthenticated curl command targeting the vulnerable endpoint. No authentication, session cookie, or API key is required, making exploitation trivial for any attacker who can reach the server. There is no evidence of in-the-wild exploitation at this time, and no threat actor attribution has been reported. The EPSS score is approximately 0.034% (0.000340), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA KEV catalog (AVideo Advisory).

Exploitation steps

  1. Reconnaissance: Identify AVideo instances (version ≤ 26.0) exposed to the internet using search engines or tools like Shodan, looking for the AVideo web interface.
  2. Discover Bitcoin addresses: Monitor the Bitcoin blockchain for transactions to wallet addresses associated with the target AVideo platform (e.g., by observing payment flows to known platform wallets or reviewing public blockchain explorers).
  3. Query the vulnerable endpoint: Send an unauthenticated HTTP GET request to the check.php endpoint with a known Bitcoin address: curl "https://your-avideo-instance.com/plugin/BlockonomicsYPT/check.php?addr=<bitcoin_address>"
  4. Harvest payment data: Parse the JSON response to extract the buyer's user ID, payment amounts, transaction ID, payment status, and order timestamp — all without any credentials.
  5. Correlate identities: Cross-reference the returned users_id values with other platform data or blockchain analytics to link on-chain transactions to specific platform users (AVideo Advisory).

Indicators of compromise

  • Network: Unauthenticated HTTP GET requests to /plugin/BlockonomicsYPT/check.php with an addr query parameter from external or unexpected IP addresses; high volume of such requests from a single source may indicate enumeration.
  • Logs: Web server access logs showing requests to check.php?addr= without an associated authenticated session cookie; 200 OK responses to these requests from unauthenticated clients.
  • Application: JSON responses containing users_id, value, txid, and status fields returned to unauthenticated requestors in application-level logs if request/response logging is enabled.

Mitigation and workarounds

No patched version of AVideo has been released as of the advisory date (affected versions ≤ 26.0). The recommended fix is to add an authentication check at plugin/BlockonomicsYPT/check.php line 17: if (!User::isLogged()) { echo json_encode(["error" => "Login required"]); exit; }. As an immediate workaround, administrators should disable or remove the BlockonomicsYPT plugin (which is already tagged as deprecated by the AVideo project) or restrict access to the check.php endpoint via web server configuration (e.g., deny external access via .htaccess or firewall rules). Monitoring web server logs for unauthenticated requests to this endpoint is also advised (Github Advisory, AVideo Advisory).

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management