CVE-2026-33502Disclosure(wwbn / avideo)

LOWCVSS 8.2 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

WWBN AVideo is an open source video platform. In versions up to and including 26.0, an unauthenticated server-side request forgery vulnerability in `plugin/Live/test.php` allows any remote user to make the AVideo server send HTTP requests to arbitrary URLs. This can be used to probe localhost/internal services and, when reachable, access internal HTTP resources or cloud metadata endpoints. Commit 1e6cf03e93b5a5318204b010ea28440b0d9a5ab3 contains a patch.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • avideo

Threat summary

  • Public PoC is present in monitored signal
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 5 classified signals
  • Peaked 1d ago at 3 mentions (2026-03-23); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
avideo

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-03-21: 1Mentions · 2026-03-23: 3Mentions · 2026-04-15: 1PoC Mentioned / Linked · 2026-03-23: 1Technical Details · 2026-03-21: 1Technical Details · 2026-03-23: 3Technical Details · 2026-04-15: 103-2103-2304-15
Signal classification1 categories
Disclosure
5100.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-211
Disclosure1
2026-03-233
Disclosure3
2026-04-151
Disclosure1
Full discourse5 posts
  • DailyCVE@dailycve
    Disclosure

    🔴 AVideo, Command Injection, #CVE-2026-33502 (Critical) https://dailycve.com/avideo-command-injection-cve-2026-33502-critical/

    Post summary

    The post announces a critical command injection vulnerability in AVideo (CVE‑2026‑33502) and points to a dailyCVE article for further details.

    0000019
    181 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-33502: CRITICAL] AVideo open source video platform has a severe unauthenticated SSRF vulnerability up to version 26.0 in `plugin/Live/test.php` allowing remote attackers to send HTTP requests to ar...#cve,CVE-2026-33502,#cybersecurity https://cvefind.com/CVE-2026-33502

    Post summary

    The announcement highlights a critical unauthenticated SSRF flaw in AVideo's `plugin/Live/test.php` (vulnerable up to 26.0) but does not provide any PoC, exploit code, patch, or evidence of active exploitation.

    0000052
    606 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-33502 - Critical WWBN AVideo is an open source video platform. In versions up to and including 26.0, an unauthenticated server-side request forgery vulnerability in `plugin/Live/test.php` allows any remot... https://www.thehackerwire.com/vulnerability/CVE-2026-33502/ https://t.co/ejqejvMg3H

    Post summary

    CVE‑2026‑33502 is an unauthenticated SSRF vulnerability in WWBN AVideo's plugin/Live/test.php, flagged as critical; no PoC, exploit, or mitigation details are provided.

    0000051
    144 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-33502: AVideo has Unauthenticated SSRF ... AVideo's test.php endpoint hands attackers a golden ticket to your internal network - unauthenticated SSRF means instan... https://zerodaysignal.com/vulnerability/CVE-2026-33502 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces a new unauthenticated SSRF vulnerability (CVE-2026-33502) in AVideo, linking to a vulnerability page that likely contains technical details.

    0000056
    162 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    An unauthenticated SSRF vulnerability (CVE-2026-33502) affects `AVideo`, potentially allowing internal network access. Investigate server isolation and egress filtering. #AVideo #SSRF #infosec https://www.pulsepatch.io/posts/cve-2026-33502-avideo-unauthenticated-ssrf

    Post summary

    CVE-2026-33502 is an unauthenticated SSRF flaw in AVideo that could enable internal network access, but no PoC, exploit code, patch information, or evidence of active exploitation is provided.

    0000037
    2 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appwwbnavideo---

Explore more