Improper Restriction of Excessive Authentication Attempts in AVideo - CVE-2026-33763

 

Improper Restriction of Excessive Authentication Attempts in AVideo - CVE-2026-33763

Published: April 8, 2026


Vulnerability identifier: #VU125478
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-33763
CWE-ID: CWE-307
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper restriction of excessive authentication attempts in the get_api_video_password_is_correct API endpoint when handling password-verification requests for password-protected videos. A remote attacker can send repeated password guesses and use the boolean passwordIsCorrect response to disclose sensitive information.

The endpoint is reachable without authentication and requires no user interaction.


Affected software

AVideo

How to mitigate CVE-2026-33763

Install security update from vendor's website.

AVideo - update to 29.0

External References

Related Security Bulletins