CVE-2026-33717Disclosure(wwbn / avideo)

LOWCVSS 8.8 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch wwbn avideo systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `downloadVideoFromDownloadURL()` function in `objects/aVideoEncoder.json.php` saves remote content to a web-accessible temporary directory using the original URL's filename and extension (including `.php`). By providing an invalid `resolution` parameter, an attacker triggers an early `die()` via `forbiddenPage()` before the temp file can be moved or cleaned up, leaving an executable PHP file persistently accessible under the web root at `videos/cache/tmpFile/`. Commit 6da79b43484099a0b660d1544a63c07b633ed3a2 contains a patch.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-434

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • avideo

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
avideo

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-03-23: 3Patch / Workaround · 2026-03-23: 1Technical Details · 2026-03-23: 303-23
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-33717 - AVideo Vulnerable to Remote Code Execution via Persistent PHP Temp File in Encoder downloadURL with Resolution Validation Abort Intel Report: https://ift.tt/vhBHM16

    Post summary

    The mention is a straightforward disclosure of CVE-2026-33717, detailing a remote code execution flaw in AVideo via a PHP temp file, but provides no PoC, exploit code, or patch information.

    0000028
    289 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-33717: HIGH] 🔒⚠️ Cyber security alert! WWBN AVideo platform versions up to 26.0 have a vulnerability allowing unauthorized access to executable PHP files. Patch available in commit 6da79b43484099a0...#cve,CVE-2026-33717,#cybersecurity https://cvefind.com/CVE-2026-33717

    Post summary

    The post announces a high severity vulnerability in WWBN AVideo that permits unauthorized access to PHP files and provides a patch commit reference.

    0000051
    606 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-33717 - High WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `downloadVideoFromDownloadURL()` function in `objects/aVideoEncoder.json.php` saves remote content to a... https://www.thehackerwire.com/vulnerability/CVE-2026-33717/ https://t.co/PX2KBL1Gjz

    Post summary

    The tweet announces a new high‑severity vulnerability in WWBN AVideo, providing technical details about the affected function but no PoC, exploit code, patch, or evidence of active exploitation.

    0000041
    145 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appwwbnavideo---

Explore more