LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-33037

wwbn · avideo

Published
CVSS8.1
Severityhigh
WeaknessCWE-1188
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

WWBN AVideo is an open source video platform. In versions 25.0 and below, the official Docker deployment files (docker-compose.yml, env.example) ship with the admin password set to "password", which is automatically used to seed the admin account during installation, meaning any instance deployed without overriding SYSTEM_ADMIN_PASSWORD is immediately vulnerable to trivial administrative takeover. No compensating controls exist: there is no forced password change on first login, no complexity validation, no default-password detection, and the password is hashed with weak MD5. Full admin access enables user data exposure, content manipulation, and potential remote code execution via file uplo

References

← Back to the CVE Tracker

Our coverage of CVE-2026-33037

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-33037.