Improper Restriction of Excessive Authentication Attempts in AVideo - CVE-2026-33763

 

Improper Restriction of Excessive Authentication Attempts in AVideo - CVE-2026-33763

Published: April 8, 2026


Vulnerability identifier: #VU125478
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2026-33763
CWE-ID: CWE-307
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: World Wide Broadcast Network
Affected software:
AVideo

Detailed vulnerability description

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper restriction of excessive authentication attempts in the get_api_video_password_is_correct API endpoint when handling password-verification requests for password-protected videos. A remote attacker can send repeated password guesses and use the boolean passwordIsCorrect response to disclose sensitive information.

The endpoint is reachable without authentication and requires no user interaction.


How to mitigate CVE-2026-33763

Install security update from vendor's website.

Sources