PT-2026-51432 · Wwbn+2 · Avideo+1
CVE-2026-33684
·
Published
2026-06-22
·
Updated
2026-07-15
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
WWBN AVideo versions prior to 29.0
Description
Privilege escalation is possible through unguarded permission parameters in the
signUp API. The set api signUp() function in the API plugin accepts user-supplied input for the emailVerified, canUpload, canStream, and canCreateMeet variables and applies them to new accounts without verifying that the request was authenticated with a valid APISecret. Consequently, any anonymous user who can solve a CAPTCHA can self-grant elevated permissions during registration. This allows attackers to bypass email-gated functionality by marking accounts as verified without owning the email address and circumvent administrator access controls to gain unauthorized upload, streaming, and meeting-creation capabilities.Recommendations
Update WWBN AVideo to version 29.0.
As a temporary workaround, restrict access to the
signUp API endpoint to prevent unauthorized registration attempts until the update is applied.Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Avideo
Wwbn Avideo