CVE-2026-33501Disclosure(wwbn / avideo)

LOWCVSS 5.3 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch wwbn avideo systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the endpoint `plugin/Permissions/View/Users_groups_permissions/list.json.php` lacks any authentication or authorization check, allowing unauthenticated users to retrieve the complete permission matrix mapping user groups to plugins. All sibling endpoints in the same directory (`add.json.php`, `delete.json.php`, `index.php`) properly require `User::isAdmin()`, indicating this is an oversight. Commits dc3c825734628bb32550d0daa125f05bacb6829c and b583acdc9a9d1eab461543caa363e1a104fb4516 contain patches.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • avideo

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-03-23); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
avideo

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-03-22: 1Mentions · 2026-03-23: 2Mentions · 2026-03-25: 1PoC Mentioned / Linked · 2026-03-22: 1Patch / Workaround · 2026-03-25: 1Technical Details · 2026-03-23: 2Technical Details · 2026-03-25: 103-2203-2303-25
Signal classification3 categories
Disclosure
250.0%
PoC
125.0%
Patch
125.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-221
PoC1
2026-03-232
Disclosure2
2026-03-251
Patch1
Full discourse4 posts
  • Clandestine@akaclandestine
    Patch

    🚨 UPDATED ALERT: CVE-2026-33501 in AVideo – Confirmed Vulnerability (Official Patch Already Released) 🚨 WARNING FOR ANYONE USING AVideo (or who knows someone who does): The world’s most popular open-source video platform has a serious unauthorized permission information disclosure vulnerability. What we know now (official sources – NVD + GitHub): • CVE-2026-33501 • Affects ALL versions up to and including 26.0 • Vulnerable endpoint: /plugin/Permissions/View/Users_groups_permissions/list.json.php • Anyone on the internet can download the complete user groups × plugins permission mapping without any login • CVSS 5.3 (Medium) – extremely easy to exploit (literally a single curl command) Fofa searches (reports from the Chinese security community) show more than 100,000 publicly exposed instances using the simple query "AVideo" or title="AVideo". Good news: The official team has already published the patches! ✅ Fix commits: • https://github.com/WWBN/AVideo/commit/dc3c825734628bb32550d0daa125f05bacb6829c • https://github.com/WWBN/AVideo/commit/b583acdc9a9d1eab461543caa363e1a104fb4516 Official GitHub Security Advisory: https://github.com/WWBN/AVideo/security/advisories/GHSA-96qp-8cmq-jvq8 WHAT TO DO RIGHT NOW: 1. Update immediately to the latest code (apply the commits) 2. If you can’t update yet → block external access to the entire /plugin/Permissions/ directory #AVideo #CVE2026-33501 #CyberSecurity #Vulnerability #InfoSec #PatchNow #OpenSourceSecurity

    Post summary

    AVideo’s CVE-2026-33501 is an information‑disclosure flaw that can be trivially exploited; official patches are available and users are urged to update immediately.

    020631.3K
    57.0K followersView on X
  • 法友百科@fayoubaike666
    PoC

    AVideo开源视频平台 存在0day漏洞 CVE-2026-33501 全版本受影响 且官方未修复 风险评分5.3 利用门槛极 Fofa资产:"AVideo"或title="AVideo" 10万台设备被暴露 目前网上已有poc https://t.co/1NKuefQBQf

    Post summary

    CVE‑2026‑33501 is a zero‑day flaw affecting all versions of AVideo, currently unpatched; over 100,000 devices are exposed and a publicly available PoC exists.

    00080904
    1.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-33501 Unauthenticated Information Disclosure in WWBN AVideo Users Group Permissions Endpoint https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-33501

    Post summary

    The post announces CVE-2026-33501, highlighting an unauthenticated information disclosure in WWBN AVideo’s users group permissions endpoint, with no PoC, exploit, or patch details provided.

    0000048
    4.0K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-33501 - AVideo has Unauthenticated Information Disclosure of User Group Permission Mappings via Permissions Plugin Intel Report: https://ift.tt/pHnNBRo

    Post summary

    The tweet announces CVE‑2026‑33501, describing an unauthenticated information disclosure flaw in AVideo’s Permissions Plugin. No PoC, exploitation tool, patch, or active exploitation claim is included.

    0000028
    289 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appwwbnavideo---

Explore more