Vulnerability Description
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the endpoint `plugin/Permissions/View/Users_groups_permissions/list.json.php` lacks any authentication or authorization check, allowing unauthenticated users to retrieve the complete permission matrix mapping user groups to plugins. All sibling endpoints in the same directory (`add.json.php`, `delete.json.php`, `index.php`) properly require `User::isAdmin()`, indicating this is an oversight. Commits dc3c825734628bb32550d0daa125f05bacb6829c and b583acdc9a9d1eab461543caa363e1a104fb4516 contain patches.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Wwbn | Avideo | <= 26.0 |
Related Weaknesses (CWE)
References
- https://github.com/WWBN/AVideo/commit/b583acdc9a9d1eab461543caa363e1a104fb4516Patch
- https://github.com/WWBN/AVideo/commit/dc3c825734628bb32550d0daa125f05bacb6829cPatch
- https://github.com/WWBN/AVideo/security/advisories/GHSA-96qp-8cmq-jvq8ExploitMitigationVendor Advisory
FAQ
What is CVE-2026-33501?
CVE-2026-33501 is a vulnerability with a CVSS score of 5.3 (MEDIUM). WWBN AVideo is an open source video platform. In versions up to and including 26.0, the endpoint `plugin/Permissions/View/Users_groups_permissions/list.json.php` lacks any authentication or authorizat...
How severe is CVE-2026-33501?
CVE-2026-33501 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-33501?
Check the references section above for vendor advisories and patch information. Affected products include: Wwbn Avideo.