WWBN AVideo is an open source video platform. Versions 25.0 and below are vulnerable to unauthenticated application takeover through the install/checkConfiguration.php endpoint. install/checkConfiguration.php performs full application initialization: database setup, admin account creation, and configuration file write, all from an unauthenticated POST input. The only guard is checking whether videos/configuration.php already exists. On uninitialized deployments, any remote attacker can complete the installation with attacker-controlled credentials and an attacker-controlled database, gaining full administrative access. This issue has been fixed in version 26.0.
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-2f9h-23f7-8gcx AVideo affected by unauthenticated application takeover via exposed web installer on uninitialized deployments
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 20 Mar 2026 05:45:00 +0000

Type Values Removed Values Added
Description WWBN AVideo is an open source video platform. Versions 25.0 and below are vulnerable to unauthenticated application takeover through the install/checkConfiguration.php endpoint. install/checkConfiguration.php performs full application initialization: database setup, admin account creation, and configuration file write, all from an unauthenticated POST input. The only guard is checking whether videos/configuration.php already exists. On uninitialized deployments, any remote attacker can complete the installation with attacker-controlled credentials and an attacker-controlled database, gaining full administrative access. This issue has been fixed in version 26.0.
Title AVideo affected by unauthenticated application takeover via exposed web installer on uninitialized deployments
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-03-20T05:35:56.812Z

Reserved: 2026-03-17T18:10:50.210Z

Link: CVE-2026-33038

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-03-20T06:16:11.983

Modified: 2026-03-20T06:16:11.983

Link: CVE-2026-33038

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses