PT-2026-51432 · Wwbn+2 · Avideo+1

CVE-2026-33684

·

Published

2026-06-22

·

Updated

2026-07-15

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions WWBN AVideo versions prior to 29.0
Description Privilege escalation is possible through unguarded permission parameters in the signUp API. The set api signUp() function in the API plugin accepts user-supplied input for the emailVerified, canUpload, canStream, and canCreateMeet variables and applies them to new accounts without verifying that the request was authenticated with a valid APISecret. Consequently, any anonymous user who can solve a CAPTCHA can self-grant elevated permissions during registration. This allows attackers to bypass email-gated functionality by marking accounts as verified without owning the email address and circumvent administrator access controls to gain unauthorized upload, streaming, and meeting-creation capabilities.
Recommendations Update WWBN AVideo to version 29.0. As a temporary workaround, restrict access to the signUp API endpoint to prevent unauthorized registration attempts until the update is applied.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-33684
GHSA-8J8M-P79X-G4JM

Affected Products

Avideo
Wwbn Avideo