CVE-2026-33478Disclosure(wwbn / avideo)

LOWCVSS 10.0 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch wwbn avideo systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

WWBN AVideo is an open source video platform. In versions up to and including 26.0, multiple vulnerabilities in AVideo's CloneSite plugin chain together to allow a completely unauthenticated attacker to achieve remote code execution. The `clones.json.php` endpoint exposes clone secret keys without authentication, which can be used to trigger a full database dump via `cloneServer.json.php`. The dump contains admin password hashes stored as MD5, which are trivially crackable. With admin access, the attacker exploits an OS command injection in the rsync command construction in `cloneClient.json.php` to execute arbitrary system commands. Commit c85d076375fab095a14170df7ddb27058134d38c contains a patch.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78CWE-284

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • avideo

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 10 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 9 signals
  • Disclosure: 8 classified signals
  • General: 1 classified signal
  • Peaked 4d ago at 4 mentions (2026-03-23); latest day: 1
  • 10 total mentions across 6 days

Affected systems

Vendors
Products
avideo

Deep dive

Activity timeline10 mentions / 6d
01234Mentions · 2026-03-21: 1Mentions · 2026-03-23: 4Mentions · 2026-03-24: 2Mentions · 2026-03-25: 1Mentions · 2026-04-08: 1Mentions · 2026-04-09: 1PoC Mentioned / Linked · 2026-04-08: 1Patch / Workaround · 2026-03-24: 1Patch / Workaround · 2026-04-09: 1Technical Details · 2026-03-21: 1Technical Details · 2026-03-23: 4Technical Details · 2026-03-24: 1Technical Details · 2026-03-25: 1Technical Details · 2026-04-08: 1Technical Details · 2026-04-09: 103-2103-2303-2403-2504-0804-09
Signal classification3 categories
Disclosure
880.0%
General
110.0%
Patch
110.0%
Referenced assets12 URLs
Classification over time
DateTotalLabels
2026-03-211
Disclosure1
2026-03-234
Disclosure4
2026-03-242
General1Patch1
2026-03-251
Disclosure1
2026-04-081
Disclosure1
2026-04-091
Disclosure1
Full discourse10 posts
  • FOFA@fofabot
    Disclosure

    ⚠️⚠️ CVE-2026-33478 (CVSS 10.0): Unauth RCE on exposed AVideo via CloneSite chain. 🔗FOFA Link: https://en.fofa.info/result?qbase64=YXBwPSJBVmlkZW8tWW91UEhQVHViZSI= 🎯17.1K+ Results are found on http://en.fofa.info in the past year. FOFA Query: app="AVideo-YouPHPTube" 🔖Refer: https://github.com/WWBN/AVideo/security/advisories/GHSA-687q-32c6-8x68 #OSINT #FOFA #CyberSecurity #Vulnerability

    Post summary

    The post announces a severe unauthenticated RCE (CVE-2026-33478) in AVideo via CloneSite, citing a CVSS score of 10 and providing a FOFA query and GitHub advisory for reference.

    06023132.5K
    13.7K followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-33478 - critical 🚨 AVideo <= 26.0 - WWBN AVideo - Remote Code Execution > WWBN AVideo <= 26.0 contains multiple vulnerabilities in the CloneSite plugin includi... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-33478 @pdnuclei #NucleiTemplates #cve

    Post summary

    The post announces CVE‑2026‑33478 as a critical remote code execution flaw in WWBN AVideo <= 26.0’s CloneSite plugin, links to a ProjectDiscovery library for detection, but does not provide exploit code, active usage claims, or remediation details.

    00012175
    916 followersView on X
  • maruomosquit@maru1151157
    Patch

    🚨 CVE-2026-33478 (CVSS: 10.0) AVideo 26.0までのCloneSiteプラグインの複数脆弱性により、未認証でリモートコード実行可能。clones.json.phpでシークレットキー漏洩し、DBダンプ(MD5ハッシュ)を経てコマンドインジェクションでシステムコマンド実行可能。対策:バージョン更新。 https://maruomosquit.com/vulnerability/CVE-2026-33478/ #脆弱性 #セキュリティ

    Post summary

    The tweet discloses CVE-2026-33478, which allows unauthenticated remote code execution in CloneSite plugin up to AVideo 26.0 through key leakage and command injection, and recommends upgrading the plugin to mitigate the vulnerability.

    0003072
    1.7K followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    An unauthenticated RCE vulnerability (CVE-2026-33478) affects `AVideo`. Attackers can achieve remote code execution via a multi-chain exploit involving key disclosure and command injection. Restrict network access. #RCE #AVideo #infosec https://www.pulsepatch.io/posts/cve-2026-33478-avideo-unauth-rce

    Post summary

    The post details an unauthenticated RCE vulnerability (CVE‑2026‑33478) in AVideo, describing its multi‑step exploitation chain and recommending network restriction as a workaround, but it does not provide a PoC or evidence of active exploitation.

    0000043
    11 followersView on X
  • CTIWatch@ctiwatchcloud
    General

    🔍 Today's Top Vulnerabilities 🔴 CVE-2026-4745 | CVSS 10.0 🔴 CVE-2026-4746 | CVSS 10.0 🔴 CVE-2026-33478 | CVSS 10.0 🔗 http://ctiwatch.cloud/vulnerabilities #CVE #Vulnerability #ThreatIntel

    Post summary

    The tweet lists three CVEs with CVSS 10.0, but offers no additional technical details, PoCs, exploit code, or evidence of active exploitation.

    0000055
    5.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-33478 Remote Code Execution in WWBN AVideo Platform via Chained Vulnerabilities https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-33478

    Post summary

    The source provides a brief disclosure of a new RCE vulnerability (CVE‑2026‑33478) affecting the WWBN AVideo Platform, but lacks detailed technical information, PoC, or exploitation evidence.

    0000075
    4.0K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-33478: CRITICAL] AVideo's CloneSite plugin vulnerabilities up to version 26.0 risk remote code execution. Attackers can access sensitive data, such as unencrypted passwords, via exposed endpoints. ...#cve,CVE-2026-33478,#cybersecurity https://cvefind.com/CVE-2026-33478

    Post summary

    The post announces a CVE-2026-33478 vulnerability in AVideo's CloneSite plugin, highlighting a remote code execution risk that allows attackers to access sensitive data through exposed endpoints, affecting versions up to 26.0.

    0000040
    606 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-33478 - Critical WWBN AVideo is an open source video platform. In versions up to and including 26.0, multiple vulnerabilities in AVideo's CloneSite plugin chain together to allow a completely unauthentica... https://www.thehackerwire.com/vulnerability/CVE-2026-33478/ https://t.co/QDCXNcXUD0

    Post summary

    A new critical CVE in WWBN AVideo’s CloneSite plugin chain allows unauthenticated exploitation, with initial details announced in the linked article; no evidence of active exploitation or available patch is provided.

    0000029
    144 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-33478: AVideo Multi-Chain Attack: Unaut... Perfect storm: exposed clone keys → DB dump → cracked MD5 hashes → command injection RCE, all without auth on 10.0 CVSS... https://zerodaysignal.com/vulnerability/CVE-2026-33478 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet alerts to CVE‑2026‑33478, outlining a chain that leads to unauthenticated command injection via exposed clone keys, DB dump, and MD5 cracking. No PoC, exploit code, patch, or evidence of active use is referenced.

    0000061
    162 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    `AVideo` is vulnerable to unauthenticated RCE via a multi-chain attack (CVE-2026-33478). This involves clone key disclosure, database dump, and command injection. Review security posture. #infosec #RCE #Vulnerability https://www.pulsepatch.io/posts/cve-2026-33478-avideo-multi-chain-rce-vulnerability

    Post summary

    The post announces that AVideo is vulnerable to unauthenticated RCE via a multi-chain attack, outlining key exploit vectors and technical details.

    0000041
    2 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appwwbnavideo---

Explore more