CVE-2026-33650Incorrect Authorization in Avideo

Severity
7.6HIGHNVD
EPSS
0.0%
top 90.69%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 23
Latest updateMar 25

Description

WWBN AVideo is an open source video platform. In versions up to and including 26.0, a user with the "Videos Moderator" permission can escalate privileges to perform full video management operations — including ownership transfer and deletion of any video — despite the permission being documented as only allowing video publicity changes (Active, Inactive, Unlisted). The root cause is that `Permissions::canModerateVideos()` is used as an authorization gate for full video editing in `videoAddNew.js

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:LExploitability: 2.8 | Impact: 4.7

Affected Packages2 packages

NVDwwbn/avideo26.0
Packagistwwbn/avideo26.0

Patches

🔴Vulnerability Details

2
GHSA
AVideo: Video Moderator Privilege Escalation via Ownership Transfer Enables Arbitrary Video Deletion2026-03-25
OSV
AVideo: Video Moderator Privilege Escalation via Ownership Transfer Enables Arbitrary Video Deletion2026-03-25

🕵️Threat Intelligence

1
Wiz
CVE-2026-33650 Impact, Exploitability, and Mitigation Steps | Wiz