#VU125446 Authorization bypass through user-controlled key in AVideo - CVE-2026-33297
Published: April 8, 2026
AVideo
World Wide Broadcast Network
Description
The vulnerability allows a remote user to bypass channel-level access control and disclose protected content.
The vulnerability exists due to improper access control in the setPassword.json.php endpoint of the CustomizeUser plugin when processing administrator-supplied ProfilePassword values for another user's channel. A remote privileged user can submit a non-numeric password for another user's channel to bypass channel-level access control and disclose protected content.
Any visitor who enters 0 as the channel password can access the affected channel content.