Missing Authentication for Critical Function in AVideo - CVE-2026-33038
Published: April 8, 2026
AVideo
Detailed vulnerability description
The vulnerability allows a remote attacker to gain full administrative access to the application.
The vulnerability exists due to missing authentication for critical function in install/checkConfiguration.php when processing unauthenticated POST requests on uninitialized deployments. A remote attacker can send a specially crafted POST request to gain full administrative access to the application.
Exploitation is possible only when the deployment is in an uninitialized state and videos/configuration.php does not yet exist.