LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-33354

wwbn · avideo

Published
CVSS7.6
Severityhigh
WeaknessCWE-73
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L

Description

WWBN AVideo is an open source video platform. In versions up to and including 26.0, `POST /objects/aVideoEncoder.json.php` accepts a requester-controlled `chunkFile` parameter intended for staged upload chunks. Instead of restricting that path to trusted server-generated chunk locations, the endpoint accepts arbitrary local filesystem paths that pass `isValidURLOrPath()`. That helper allows files under broad server directories including `/var/www/`, the application root, cache, tmp, and `videos`, only rejecting `.php` files. For an authenticated uploader editing their own video, this becomes an arbitrary local file read. The endpoint copies the attacker-chosen local file into the attacker's

References

← Back to the CVE Tracker

Our coverage of CVE-2026-33354

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-33354.