CVE-2026-33692
published 2026-07-16CVE-2026-33692: WWBN AVideo is an open source video platform. Versions prior to 29.0 expose .env files to unauthenticated users through the official Docker compose…
PriorityP351high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.27%
18.6th percentile
WWBN AVideo is an open source video platform. Versions prior to 29.0 expose .env files to unauthenticated users through the official Docker compose configuration. The official docker-compose.yml mounts the entire project root directory as the Apache document root, causing the .env file — which contains database credentials, admin passwords, and infrastructure configuration — to be served as a static file at /.env. No .htaccess rule or Apache configuration blocks access to dotfiles. Exploitation enables direct database access, admin panel takeover, and further lateral movement within the Docker network. This issue has been resolved in version 29.0.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| wwbn | avideo | < 29.0 | 29.0 |
| wwbn | avideo | >= 0 < 29.0 | 29.0 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
WWBN AVideo up to 28.x Apache Configuration docker-compose.yml input validation
vuldb·2026-07-16·CVSS 7.5
CVE-2026-33692 [HIGH] WWBN AVideo up to 28.x Apache Configuration docker-compose.yml input validation
A vulnerability labeled as problematic has been found in WWBN AVideo up to 28.x. Impacted is an unknown function of the file docker-compose.yml of the component Apache Configuration. Executing a manipulation can lead to improper input validation.
This vulnerability appears as CVE-2026-33692. The attack may be performed from remote. There is no available exploit.
GHSA
AVideo Vulnerable to Unauthenticated .env File Exposure via Official Docker Compose Configuration
ghsa·2026-06-22
CVE-2026-33692 [HIGH] CWE-20 AVideo Vulnerable to Unauthenticated .env File Exposure via Official Docker Compose Configuration
AVideo Vulnerable to Unauthenticated .env File Exposure via Official Docker Compose Configuration
## Vulnerability Details
**CWE**: CWE-538 - Insertion of Sensitive Information into Externally-Accessible File or Directory
The official `docker-compose.yml` (line 61) mounts the entire project root directory as the Apache document root:
```yaml
volumes:
- "./:/var/www/html/AVideo"
```
This causes the `.env` file — which contains database credentials, admin passwords, and infrastructure configuration — to be served as a static file at `/.env`. No `.htaccess` rule or Apache configuration blocks access to dotfiles.
### Exposed Information
An unauthenticated request to `GET /.env` returns:
```
DB_MYSQL_HOST=database
DB_MYSQL_USER=avideo
DB_MYSQL_PASSWORD=avideo
SYSTEM_ADMIN_PASSWORD=admin
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-07-16
Published