CVE-2026-33688

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the password recovery endpoint at `objects/userRecoverPass.php` performs user existence and account status checks before validating the captcha. This allows an unauthenticated attacker to enumerate valid usernames and determine whether accounts are active, inactive, or banned — at scale and without solving any captcha — by observing three distinct JSON error responses. Commit e42f54123b460fd1b2ee01f2ce3d4a386e88d157 contains a patch.
Configurations

Configuration 1 (hide)

cpe:2.3:a:wwbn:avideo:*:*:*:*:*:*:*:*

History

25 Mar 2026, 18:05

Type Values Removed Values Added
First Time Wwbn
Wwbn avideo
References () https://github.com/WWBN/AVideo/commit/e42f54123b460fd1b2ee01f2ce3d4a386e88d157 - () https://github.com/WWBN/AVideo/commit/e42f54123b460fd1b2ee01f2ce3d4a386e88d157 - Patch
References () https://github.com/WWBN/AVideo/security/advisories/GHSA-m99f-mmvg-3xmx - () https://github.com/WWBN/AVideo/security/advisories/GHSA-m99f-mmvg-3xmx - Exploit, Vendor Advisory
Summary
  • (es) WWBN AVideo es una plataforma de vídeo de código abierto. En versiones hasta la 26.0 inclusive, el endpoint de recuperación de contraseña en 'objects/userRecoverPass.php' realiza comprobaciones de existencia de usuario y estado de cuenta antes de validar el captcha. Esto permite a un atacante no autenticado enumerar nombres de usuario válidos y determinar si las cuentas están activas, inactivas o baneadas — a escala y sin resolver ningún captcha — al observar tres respuestas de error JSON distintas. El commit e42f54123b460fd1b2ee01f2ce3d4a386e88d157 contiene un parche.
CPE cpe:2.3:a:wwbn:avideo:*:*:*:*:*:*:*:*

24 Mar 2026, 15:16

Type Values Removed Values Added
References () https://github.com/WWBN/AVideo/security/advisories/GHSA-m99f-mmvg-3xmx - () https://github.com/WWBN/AVideo/security/advisories/GHSA-m99f-mmvg-3xmx -

23 Mar 2026, 19:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-23 19:16

Updated : 2026-03-25 18:05


NVD link : CVE-2026-33688

Mitre link : CVE-2026-33688

CVE.ORG link : CVE-2026-33688


JSON object : View

Products Affected

wwbn

  • avideo
CWE
CWE-204

Observable Response Discrepancy