CVE-2026-33478

CRITICAL EXPLOITED NUCLEI

AVideo Multi-Chain Attack: Unauthenticated Remote Code Execution via Clone Key Disclosure, Database Dump, and Command Injection

Title source: cna
STIX 2.1

Exploitation Summary

CVE-2026-33478 has been observed exploited in the wild (reported by VulnCheck KEV). A Nuclei detection template is also available.

Description

WWBN AVideo is an open source video platform. In versions up to and including 26.0, multiple vulnerabilities in AVideo's CloneSite plugin chain together to allow a completely unauthenticated attacker to achieve remote code execution. The `clones.json.php` endpoint exposes clone secret keys without authentication, which can be used to trigger a full database dump via `cloneServer.json.php`. The dump contains admin password hashes stored as MD5, which are trivially crackable. With admin access, the attacker exploits an OS command injection in the rsync command construction in `cloneClient.json.php` to execute arbitrary system commands. Commit c85d076375fab095a14170df7ddb27058134d38c contains a patch.

Nuclei Templates (1)

AVideo <= 26.0 - WWBN AVideo - Remote Code Execution
CRITICALVERIFIEDby pussycat0x
Shodan: http.html:"AVideo"
FOFA: app="AVideo-YouPHPTube"

Scores

CVSS v3 10.0
EPSS 0.0713
EPSS Percentile 91.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

VulnCheck KEV 2026-04-30
CWE
CWE-284 CWE-78
Status published
Products (4)
avideo/avideo 0Packagist
wwbn/avideo < 26.0
wwbn/avideo 0Packagist
WWBN/AVideo <= 26.0
Published Mar 23, 2026
Tracked Since Mar 23, 2026