PT-2026-26565 · Avideo · Avideo

Bugbunny-Research

·

Published

2026-03-20

·

Updated

2026-03-21

·

CVE-2026-33037

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions AVideo versions 25.0 and below
Description AVideo is an open source video platform. In versions 25.0 and below, the official Docker deployment files (docker-compose.yml, env.example) are distributed with the administrator password set to 'password'. This password is automatically used to initialize the administrator account during installation. Consequently, any instance deployed without overriding the SYSTEM ADMIN PASSWORD variable is immediately susceptible to trivial administrative takeover. There are no mitigating controls in place, such as forced password changes on first login, complexity validation, or default password detection. The password is hashed using weak MD5. Full administrator access allows for user data exposure, content manipulation, and potential remote code execution through file uploads and plugin management. The same insecure default pattern applies to database credentials (avideo/avideo), increasing the risk. Exploitation relies on operators failing to change the default value, a condition likely to occur in quick-start, demonstration, and automated deployments.
Recommendations AVideo versions prior to 26.0 should be updated to version 26.0 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-33037
GHSA-89RV-P523-6WG9

Affected Products

Avideo