Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
internet-facing-service-vulnerabilitydefault-credential-exposurewidely-deployed-product-advisoryidentity-authentication-vulnerability

Multiple Critical AVideo Flaws Enable Takeover, Session Hijacking, and SSRF

Updated 14d agoFirst seen Mar 20, 20265 sources

WWBN AVideo was found to contain multiple high-severity vulnerabilities that can let attackers seize control of deployments, hijack user sessions, and access internal network resources. On uninitialized instances running version 25.0 or earlier, install/checkConfiguration.php could be abused without authentication to complete setup, create an administrator account, and write configuration files, enabling full application takeover under CVE-2026-33038. Separate insecure defaults in the official Docker deployment path, tracked as CVE-2026-33037, left new installations exposed to immediate administrative compromise because the admin password defaulted to "password" and database credentials defaulted to avideo/avideo, with no forced password change or effective hardening.

AVideo also exposed users and infrastructure through web-facing flaws in session handling and URL fetching. Under CVE-2026-33043, /objects/phpsessionid.json.php disclosed active PHP session IDs to unauthenticated requests, and permissive CORS behavior could allow cross-origin session theft and account takeover. Two SSRF issues affected the unauthenticated plugin/LiveLinks/proxy.php endpoint: CVE-2026-33039 allowed redirect-based bypass of URL safety checks in version 25.0 and earlier, while CVE-2026-33480 showed that isSSRFSafeURL() could also be bypassed with IPv4-mapped IPv6 addresses, extending exposure through version 26.0 and enabling access to localhost, RFC1918 networks, and cloud metadata services. WWBN issued fixes in AVideo 26.0 for most of the disclosed flaws, with an additional patch published for the IPv6-based SSRF bypass.

Share:
Multiple Critical AVideo Flaws Enable Takeover, Session Hijacking, and SSRF
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

4 events from the most recent confirmed update back to the earliest known activity.

4 EVENTS
Mar 23, 20263mo ago

CVE-2026-33480 is publicly disclosed

On 2026-03-23, a public vulnerability record disclosed CVE-2026-33480, an SSRF protection bypass in AVideo's unauthenticated LiveLinks proxy using IPv4-mapped IPv6 addresses. The disclosure notes the issue affected versions up to and including 26.0.

CVE-2026-33480 - AVideo has a SSRF Protection Bypass via IPv4-Mapped IPv6 Addresses in Unauthenticated LiveLinks Proxy

AVideo SSRF bypass via IPv4-mapped IPv6 receives a patch

A separate SSRF vulnerability affecting AVideo up to and including version 26.0 was addressed with patch commit 75ce8a579a58c9d4c7aafe453fbced002cb8f373. The flaw allowed bypass of isSSRFSafeURL() using IPv4-mapped IPv6 addresses against the unauthenticated LiveLinks proxy endpoint.

CVE-2026-33480 - AVideo has a SSRF Protection Bypass via IPv4-Mapped IPv6 Addresses in Unauthenticated LiveLinks Proxy
Mar 20, 20263mo ago

Multiple AVideo CVEs are publicly disclosed

On 2026-03-20, public vulnerability records described several AVideo issues: unauthenticated installer-based takeover, redirect-based SSRF, predictable default Docker admin credentials, and unauthenticated session ID disclosure enabling hijacking. The disclosures state these issues affected AVideo 25.0 and earlier.

CVE-2026-33039 - AVideo vulnerable to unauthenticated SSRF via HTTP redirect bypass in LiveLinks proxy

WWBN fixes multiple AVideo flaws in version 26.0

WWBN released AVideo version 26.0 to fix several vulnerabilities affecting version 25.0 and earlier, including unauthenticated installer takeover, redirect-based SSRF, predictable default admin credentials, and session ID disclosure with permissive CORS.

CVE-2026-33039 - AVideo vulnerable to unauthenticated SSRF via HTTP redirect bypass in LiveLinks proxy
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

7 LINKEDOpen in app
Affected products
3 linked
AvideoAvideoAvideo
Organizations
2 linked
WwbnGitHub
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.