S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Apr 8, 2026

CVE-2026-33478 Scanner

CVE-2026-33478 Scanner - Remote Code Execution (RCE) vulnerability in AVideo

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
3.1k
Times Used
continuous scan runs
5.5k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2026-33478
10.0
CVSScritical
Exploitable remotely over the internet · no authentication required.

WWBN AVideo is an open source video platform. In versions up to and including 26.0, multiple vulnerabilities in AVideo's CloneSite plugin chain together to allow a completely unauthenticated attacker to achieve remote code execution. The `clones.json.php` endpoint exposes clone secret keys without authentication, which can be used to trigger a full database dump via `cloneServer.json.php`. The dump contains admin password hashes stored as MD5, which are trivially crackable. With admin access, the attacker exploits an OS command injection in the rsync command construction in `cloneClient.json.php` to execute arbitrary system commands. Commit c85d076375fab095a14170df7ddb27058134d38c contains a patch.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
AVideoby WWBN
<= 26.0
Updated Aug 22, 2026View on NVD →
Detail

AVideo is an online platform that allows users to host, manage, and stream video content. It's widely used by content creators, businesses, and educational institutions for its ease of use and versatility in video content management. The platform supports several plugins to extend its functionality, enabling users to integrate various third-party services. AVideo is often deployed on private servers, providing greater control over video assets, user data, and custom branding. It is designed to handle a variety of video formats and can be customized through open-source contributions. However, its extensibility also poses risks if plugins are not properly secured, making the platform a potential target for vulnerabilities.

The Remote Code Execution (RCE) vulnerability in AVideo enables attackers to execute arbitrary code on the server running the application. This vulnerability arises due to improper construction of system commands, allowing unauthorized users to inject malicious code. Such vulnerabilities are critical as they can lead to a complete server compromise and unauthorized data access. This specific RCE vulnerability affects the CloneSite plugin within AVideo, exposing the system to potential exploitation. Attackers exploiting this vulnerability can bypass authentication mechanisms to execute the code of their choice. The consequences of such exploits can be severe, ranging from data theft to full control of the application environment.

Technical details about this RCE vulnerability reveal that attackers exploit command injection in the CloneSite plugin's rsync command construction. The vulnerability allows unauthenticated users to expose clone secret keys, subsequently allowing command execution. Affected endpoints can include parts of the application that interact with system-level commands, intended for cloning or replication tasks. Vulnerable parameters may include those passed to system utility commands, where improper sanitization leads to injection opportunities. This vulnerability is of significant concern, especially when exposed to public networks without additional access controls. Proper patching and command sanitization are crucial to preventing this vulnerability from being exploited.

If this RCE vulnerability is exploited, attackers can achieve full server compromise by executing arbitrary system commands. This can lead to severe implications such as unauthorized data extraction, modification, or deletion. Exploiters could install backdoors, enabling persistent access to the server for future attacks potentially. System performance may also degrade as malicious code consumes resources or propagates further malware. The trust relationship between service providers and users can be damaged if user data is compromised due to such vulnerabilities. Moreover, exploited systems may also be leveraged in larger-scale attacks, such as Distributed Denial of Service (DDoS) or spreading ransomware.

REFERENCES

Solution Advice
  • Update AVideo to the version including commit c85d076375fab095a14170df7ddb27058134d38c or later.
  • Regularly audit plugin configurations and access permissions.
  • Implement network-level access controls to restrict unauthorized access to sensitive application endpoints.
  • Utilize Web Application Firewalls (WAF) to detect and block suspicious activities related to command injection.
  • Educate your development and IT team about secure coding practices and vulnerability management.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.