Signature Verification Bypass in WWBN AVideo Open Source Video Platform
CVE-2026-33731
What is CVE-2026-33731?
WWBN AVideo, an open source video platform, suffers from a vulnerability due to a bypass in the Authorize.Net webhook handler present in versions prior to 29.0. This flaw allows attackers to forge webhook requests, manipulating payment amounts and targeting user IDs without proper authentication. By leveraging a legitimate transaction ID, an attacker can bypass necessary signature validation, leading to unauthorized crediting of user wallets and enabling free access to paid and premium content. An exploit chain is formed through three specific flaws, including improper payload value handling and absent approval checks. This vulnerability represents a substantial risk of financial loss for the platform owner and affects user account security. The issue was rectified in version 29.0.
Affected Version(s)
AVideo < 29.0
