#VU125460 Missing Authorization in AVideo - CVE-2026-33501
Published: April 8, 2026
AVideo
World Wide Broadcast Network
Description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to missing authorization in plugin/Permissions/View/Users_groups_permissions/list.json.php when handling direct requests to the permissions listing endpoint. A remote attacker can send a request to retrieve the complete permission matrix mapping user groups to plugins and disclose sensitive information.
The endpoint returns JSON data from the users_groups_permissions table, including group IDs, plugin IDs, permission types, and active or inactive status.