PT-2026-27168 · Wwbn · Avideo

Published

2026-03-23

·

Updated

2026-03-23

·

CVE-2026-33513

CVSS v3.1

8.6

High

AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
WWBN AVideo is an open source video platform. In versions up to and including 26.0, an unauthenticated API endpoint (APIName=locale) concatenates user input into an include path with no canonicalization or whitelist. Path traversal is accepted, so arbitrary PHP files under the web root can be included. In our test this yielded confirmed file disclosure and code execution of existing PHP content (e.g., view/about.php), and it can escalate to RCE if an attacker can place or control a PHP file elsewhere in the tree. As of time of publication, no patched versions are available.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2026-33513

Affected Products

Avideo