#VU125441 Missing Authentication for Critical Function in AVideo - CVE-2026-33038
Published: April 8, 2026
AVideo
World Wide Broadcast Network
Description
The vulnerability allows a remote attacker to gain full administrative access to the application.
The vulnerability exists due to missing authentication for critical function in install/checkConfiguration.php when processing unauthenticated POST requests on uninitialized deployments. A remote attacker can send a specially crafted POST request to gain full administrative access to the application.
Exploitation is possible only when the deployment is in an uninitialized state and videos/configuration.php does not yet exist.