API Authentication Bypass in WWBN AVideo Open Source Video Platform
CVE-2026-33512
7.5HIGH
What is CVE-2026-33512?
The WWBN AVideo platform, an open source video management solution, contains a vulnerability in its API plugin that allows unauthenticated users to invoke a decryptString action. This flaw enables any user to submit ciphertext and obtain the corresponding plaintext, potentially compromising sensitive tokens and metadata. Given that the ciphertext can be accessed publicly via endpoints like view/url2Embed.json.php, this vulnerability raises significant concerns for data security and confidentiality. A patch has been issued to address this issue; users are encouraged to update to the latest version to mitigate the risk.
Affected Version(s)
AVideo <= 26.0
