Information disclosure in AVideo - CVE-2026-33041

 

Information disclosure in AVideo - CVE-2026-33041

Published: May 4, 2026


Vulnerability identifier: #VU129506
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-33041
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to exposure of sensitive information to an unauthorized actor in objects/encryptPass.json.php when handling password hash requests. A remote attacker can submit arbitrary passwords to obtain their hashed equivalents to disclose sensitive information.

By default, salt is not enabled, making the returned hash deterministic and identical to what is stored in the database.


Affected software

AVideo

How to mitigate CVE-2026-33041

Install security update from vendor's website.

AVideo - update to 14.3.1

External References

Related Security Bulletins