CVE-2026-35449: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-35449 is an unauthenticated information disclosure vulnerability in WWBN AVideo affecting all versions up to and including 26.0. The install/test.php diagnostic script has its CLI-only access guard disabled — the die() statement is commented out — leaving the script accessible via HTTP after installation. This exposes video viewer statistics including IP addresses, session IDs, and user agents to any unauthenticated visitor. Disclosed on April 2, 2026 by aisafe.io and published to the GitHub Advisory Database on April 4, 2026, it carries a CVSS v3.1 base score of 5.3 (Medium) (GitHub Advisory, AVideo Advisory).

Technical details

The root cause is CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor). In install/test.php lines 5–7, the intended CLI-only guard if (!isCommandLineInterface()) { return die('Command Line only'); } has its die() call commented out, allowing HTTP access. The script additionally sets error_reporting(E_ALL) and ini_set('display_errors', '1'), then calls VideoStatistic::getLastStatistics() and outputs results via var_dump(), exposing a VideoStatistic object containing ip, session_id, user_agent, users_id, and JSON metadata. The install/ directory's .htaccess only disables directory listing (Options -Indexes) and does not block direct access to individual PHP files, so no additional server-side controls prevent exploitation (GitHub Advisory).

Impact

Successful exploitation allows any unauthenticated remote attacker to retrieve viewer IP addresses (constituting PII under GDPR), session identifiers, and user agents for any video ID by supplying a videos_id parameter. The display_errors=1 setting additionally leaks internal server filesystem paths in PHP warnings, which could aid further reconnaissance. There is no integrity or availability impact; the risk is limited to confidentiality of viewer data and server path disclosure (AVideo Advisory).

Exploitability

A proof-of-concept exploit is publicly available in the GitHub Security Advisory, consisting of a simple curl command requiring no authentication, credentials, or special tooling. The vulnerability has been confirmed accessible on live AVideo instances returning HTTP 200. As of the time of reporting, there is no evidence of active in-the-wild exploitation, no known threat actor attribution, and the CVE is not listed in the CISA KEV catalog. The EPSS score is approximately 0.028% (0.000280), indicating a low near-term exploitation probability (AVideo Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing AVideo instances (versions ≤ 26.0) using search engines like Shodan or Censys, or by browsing to known AVideo deployments.
  2. Verify endpoint accessibility: Send an HTTP GET request to https://<target>/install/test.php to confirm the script returns HTTP 200 rather than a CLI-only error.
  3. Extract viewer statistics: Issue a targeted request with a valid videos_id parameter to retrieve viewer data:
    curl "https://your-avideo-instance.com/install/test.php?videos_id=1"
  4. Parse the response: The var_dump() output will contain a VideoStatistic object with fields including ip (viewer IP address), session_id, user_agent, users_id, and JSON metadata.
  5. Harvest additional data: Iterate over different videos_id values to enumerate statistics for multiple videos and collect PII across the platform.
  6. Leverage path disclosure: Trigger PHP warnings (e.g., by supplying invalid parameters) to extract internal filesystem paths from verbose error output, which can inform further attack planning (AVideo Advisory).

Indicators of compromise

  • Network: Unusual HTTP GET requests to /install/test.php with a videos_id query parameter from external or unexpected IP addresses; high-frequency enumeration of this endpoint with incrementing videos_id values.
  • Logs: Web server access logs showing GET /install/test.php?videos_id=<N> returning HTTP 200 from unauthenticated clients; PHP error logs showing verbose output or warnings triggered by malformed parameters.
  • File System: Presence of an unmodified install/test.php with the die() statement commented out (lines 5–7) on a production AVideo instance post-installation (AVideo Advisory).

Mitigation and workarounds

No patched version of AVideo has been released as of the advisory publication date; the advisory lists "None" for patched versions. The recommended immediate fix is to uncomment the CLI guard in install/test.php line 6, restoring: if (!isCommandLineInterface()) { return die('Command Line only'); }. As additional workarounds, administrators should restrict HTTP access to the install/ directory via web server configuration (e.g., deny all external access in Apache/Nginx), or remove the install/ directory entirely from production deployments. Setting display_errors = Off in php.ini will also prevent filesystem path leakage (AVideo Advisory, GitHub Advisory).

Community reactions

The vulnerability was discovered and reported by aisafe.io and published by DanielnetoDotCom to the WWBN/AVideo repository. Coverage has appeared on vulnerability aggregation platforms including VulDB, CVEFeed, and Infinit Security, with the latter publishing a dedicated write-up. No significant vendor statement beyond the advisory itself, nor notable researcher commentary or social media discussion, has been observed (GitHub Advisory).

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management