CVE-2026-33513Disclosure(wwbn / avideo)

LOWCVSS 7.5 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

WWBN AVideo is an open source video platform. In versions up to and including 26.0, an unauthenticated API endpoint (`APIName=locale`) concatenates user input into an `include` path with no canonicalization or whitelist. Path traversal is accepted, so arbitrary PHP files under the web root can be included. In our test this yielded confirmed file disclosure and code execution of existing PHP content (e.g., `view/about.php`), and it *can* escalate to RCE if an attacker can place or control a PHP file elsewhere in the tree. As of time of publication, no patched versions are available.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22CWE-98

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • avideo

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
avideo

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-03-23: 3Technical Details · 2026-03-23: 303-23
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-33513 - AVideo has an Unauthenticated Local File Inclusion in API locale (RCE possible with writable PHP) Intel Report: https://ift.tt/8mMVikp

    Post summary

    A new CVE (CVE-2026-33513) for the AVideo platform has been disclosed, exposing an unauthenticated local file inclusion that could allow RCE via writable PHP. The linked intel report provides further details.

    0000028
    289 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-33513: HIGH] Warning: Vulnerability in WWBN AVideo up to v26.0 allows unauthenticated path traversal & file disclosure, leading to possible code execution. Patch not yet available.#cve,CVE-2026-33513,#cybersecurity https://cvefind.com/CVE-2026-33513

    Post summary

    A new vulnerability (CVE‑2026‑33513) in WWBN AVideo up to v26.0 permits unauthenticated path traversal that can lead to code execution, with no patch released yet.

    0000045
    606 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-33513 - High WWBN AVideo is an open source video platform. In versions up to and including 26.0, an unauthenticated API endpoint (`APIName=locale`) concatenates user input into an `include` path with no c... https://www.thehackerwire.com/vulnerability/CVE-2026-33513/ https://t.co/nljkyHcvcW

    Post summary

    The post merely discloses a new high‑severity CVE in WWBN AVideo, describing the affected unauthenticated API endpoint and how user input is mishandled.

    0000039
    145 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appwwbnavideo---

Explore more