Improper Authentication in AVideo - CVE-2026-33512

 

Improper Authentication in AVideo - CVE-2026-33512

Published: April 8, 2026


Vulnerability identifier: #VU125467
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-33512
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper authentication in the API plugin decryptString action when handling crafted requests to the unauthenticated API endpoint. A remote attacker can submit ciphertext to recover plaintext and disclose sensitive information.

Publicly accessible ciphertext returned by url2Embed.json.php can be decrypted through this oracle.


Affected software

AVideo

How to mitigate CVE-2026-33512

Install security update from vendor's website.

AVideo - update to 29.0

External References

Related Security Bulletins