Insecure Default Initialization of Resource in AVideo - CVE-2026-33037

 

Insecure Default Initialization of Resource in AVideo - CVE-2026-33037

Published: April 8, 2026


Vulnerability identifier: #VU125440
CSH Severity: High
CVSS v4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-33037
CWE-ID: CWE-1188
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain administrative access to the application.

The vulnerability exists due to insecure default initialization of resource in the official Docker deployment manifests and automated installer when deploying AVideo without overriding the default admin password. A remote attacker can log in with the predictable default admin credential to gain administrative access to the application.

Exploitation depends on deployments that retain the default SYSTEM_ADMIN_PASSWORD value during installation.


Affected software

AVideo

How to mitigate CVE-2026-33037

Install security update from vendor's website.

AVideo - update to 24.0

External References

Related Security Bulletins