CVE Explorer
CVE-2026-33719
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the CDN plugin endpoints `plugin/CDN/status.json.php` and `plugin/CDN/disable.json.php` use key-based authentication with an empty string default key. When the CDN plugin is enabled but the key has not been configured (the default state), the key validation check is completely bypassed, allowing any unauthenticated attacker to modify the full CDN configuration — including CDN URLs, storage credentials, and the au
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"AVideo","vendor":"WWBN","versions":[{"status":"affected","version":"<= 26.0"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:692d444aacb451d76db26fdf2d839f21501a77d8fce332b3028acb008125c709 · sha256:6d7ad8a255b885e7… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"LOW","baseScore":8.6,"baseSeverity":"HIGH","confidentialityImpact":"LOW","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:692d444aacb451d76db26fdf2d839f21501a77d8fce332b3028acb008125c709 · sha256:6d7ad8a255b885e7… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-306","description":"CWE-306: Missing Authentication for Critical Function","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:692d444aacb451d76db26fdf2d839f21501a77d8fce332b3028acb008125c709 · sha256:6d7ad8a255b885e7… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"name":"https://github.com/WWBN/AVideo/commit/adeff0a31ba04a56f411eef256139fd7ed7d4310","tags":["x_refsource_MISC"],"url":"https://github.com/WWBN/AVideo/commit/adeff0a31ba04a56f411eef256139fd7ed7d4310"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:692d444aacb451d76db26fdf2d839f21501a77d8fce332b3028acb008125c709 · sha256:6d7ad8a255b885e7… · /containers/cna/references/1
{"name":"https://github.com/WWBN/AVideo/security/advisories/GHSA-r64r-883r-wcwh","tags":["x_refsource_CONFIRM"],"url":"https://github.com/WWBN/AVideo/security/advisories/GHSA-r64r-883r-wcwh"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:692d444aacb451d76db26fdf2d839f21501a77d8fce332b3028acb008125c709 · sha256:6d7ad8a255b885e7… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.