PHP Bug in AVideo Installation Script Allows Unauthorized Access
CVE-2026-34733

6.5MEDIUM

Key Information:

Vendor

Wwbn

Status
Vendor
CVE Published:
31 March 2026

What is CVE-2026-34733?

The AVideo platform, a widely-used open source video hosting solution, contains a significant vulnerability in its installation script, specifically in the file install/deleteSystemdPrivate.php. This script, which is designed to be executed only from the command line interface (CLI), suffers from a PHP operator precedence issue. The faulty guard condition does not properly restrict access, allowing unauthorized users to invoke the script via HTTP requests. This oversight not only enables the deletion of files from the server's temporary directory but also exposes the contents of this directory in the response, creating significant security risks. As of now, there are no known patches available to address this vulnerability.

Affected Version(s)

AVideo <= 26.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.