CVE-2026-33647Disclosure(wwbn / avideo)

LOWCVSS 8.8 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch wwbn avideo systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `ImageGallery::saveFile()` method validates uploaded file content using `finfo` MIME type detection but derives the saved filename extension from the user-supplied original filename without an allowlist check. An attacker can upload a polyglot file (valid JPEG magic bytes followed by PHP code) with a `.php` extension. The MIME check passes, but the file is saved as an executable `.php` file in a web-accessible directory, achieving Remote Code Execution. Commit 345a8d3ece0ad1e1b71a704c1579cbf885d8f3ae contains a patch.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-434

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • avideo

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
avideo

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-03-23: 3Patch / Workaround · 2026-03-23: 1Technical Details · 2026-03-23: 303-23
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-33647 - AVideo Vulnerable to Remote Code Execution via MIME/Extension Mismatch in ImageGallery File Upload Intel Report: https://ift.tt/hxWeZDj

    Post summary

    CVE-2026-33647 is a remote code execution vulnerability in AVideo caused by a MIME/Extension mismatch during image gallery file upload, with no PoC, exploit tool, patch, or active exploitation reported.

    0000032
    289 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-33647 - High WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `ImageGallery::saveFile()` method validates uploaded file content using `finfo` MIME type detection but... https://www.thehackerwire.com/vulnerability/CVE-2026-33647/ https://t.co/4YMHQmX1eo

    Post summary

    A high‑severity vulnerability (CVE‑2026‑33647) has been announced in WWBN AVideo’s ImageGallery::saveFile method, where MIME type validation via finfo is insufficient, though no PoC or exploitation details are provided.

    0000089
    145 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-33647: HIGH] Open source video platform WWBN AVideo had a cyber security flaw up to version 26.0 allowing Remote Code Execution. Upgrade to commit 345a8d3ece0ad1e1b71a704c1579cbf885d8f3ae for patch.#cve,CVE-2026-33647,#cybersecurity https://cvefind.com/CVE-2026-33647

    Post summary

    The post announces a remote code execution flaw in WWBN AVideo up to v26.0 and gives a specific commit for patching, confirming the CVE.

    0000044
    606 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appwwbnavideo---

Explore more