WWBN AVideo was found to contain multiple high-severity vulnerabilities that can let attackers seize control of deployments, hijack user sessions, and access internal network resources. On uninitialized instances running version 25.0 or earlier, install/checkConfiguration.php could be abused without authentication to complete setup, create an administrator account, and write configuration files, enabling full application takeover under CVE-2026-33038. Separate insecure defaults in the official Docker deployment path, tracked as CVE-2026-33037, left new installations exposed to immediate administrative compromise because the admin password defaulted to "password" and database credentials defaulted to avideo/avideo, with no forced password change or effective hardening.
AVideo also exposed users and infrastructure through web-facing flaws in session handling and URL fetching. Under CVE-2026-33043, /objects/phpsessionid.json.php disclosed active PHP session IDs to unauthenticated requests, and permissive CORS behavior could allow cross-origin session theft and account takeover. Two SSRF issues affected the unauthenticated plugin/LiveLinks/proxy.php endpoint: CVE-2026-33039 allowed redirect-based bypass of URL safety checks in version 25.0 and earlier, while CVE-2026-33480 showed that isSSRFSafeURL() could also be bypassed with IPv4-mapped IPv6 addresses, extending exposure through version 26.0 and enabling access to localhost, RFC1918 networks, and cloud metadata services. WWBN issued fixes in AVideo 26.0 for most of the disclosed flaws, with an additional patch published for the IPv6-based SSRF bypass.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
On 2026-03-23, a public vulnerability record disclosed CVE-2026-33480, an SSRF protection bypass in AVideo's unauthenticated LiveLinks proxy using IPv4-mapped IPv6 addresses. The disclosure notes the issue affected versions up to and including 26.0.
A separate SSRF vulnerability affecting AVideo up to and including version 26.0 was addressed with patch commit 75ce8a579a58c9d4c7aafe453fbced002cb8f373. The flaw allowed bypass of isSSRFSafeURL() using IPv4-mapped IPv6 addresses against the unauthenticated LiveLinks proxy endpoint.
On 2026-03-20, public vulnerability records described several AVideo issues: unauthenticated installer-based takeover, redirect-based SSRF, predictable default Docker admin credentials, and unauthenticated session ID disclosure enabling hijacking. The disclosures state these issues affected AVideo 25.0 and earlier.
WWBN released AVideo version 26.0 to fix several vulnerabilities affecting version 25.0 and earlier, including unauthenticated installer takeover, redirect-based SSRF, predictable default admin credentials, and session ID disclosure with permissive CORS.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.