CVE-2026-33684
Last modified
CVE-2026-33684 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. WWBN AVideo is an open source video platform. Prior to version 29.0, Privilege Escalation is possible through unguarded permission parameters in signUp API, which allows any user who can solve a CAPTCHA to self-grant elevated permissions during account registration. EPSS estimates a 0.33% chance of exploitation in the next 30 days.
Description
WWBN AVideo is an open source video platform. Prior to version 29.0, Privilege Escalation is possible through unguarded permission parameters in signUp API, which allows any user who can solve a CAPTCHA to self-grant elevated permissions during account registration. The set_api_signUp method in the API plugin accepts emailVerified, canUpload, canStream, and canCreateMeet parameters from user-supplied input and applies them to newly created accounts without verifying that the request was authenticated with a valid APISecret. By self-granting account attributes, attackers can mark their own accounts as email-verified without owning the address (bypassing email-gated functionality) and award themselves upload, streaming, and meeting-creation permissions, circumventing administrator access controls that intentionally restrict these capabilities for new users. This issue has been fixed in version 29.0
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| WWBN | AVideo | < 29.0 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-33684?
How severe is CVE-2026-33684?
How do I fix CVE-2026-33684?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-33679Vikunja is an open-source self-hosted task management platfo…7.4
- CVE-2026-3368The Injection Guard plugin for WordPress is vulnerable to St…7.2
- CVE-2026-33680Vikunja is an open-source self-hosted task management platfo…6.5
- CVE-2026-33681WWBN AVideo is an open source video platform. In versions up…7.2
- CVE-2026-33682Streamlit is a data oriented application development framewo…4.8
- CVE-2026-33683WWBN AVideo is an open source video platform. In versions up…5.4
- CVE-2026-33685WWBN AVideo is an open source video platform. In versions up…5.3
- CVE-2026-33686Sharp is a content management framework built for Laravel as…8.8
- CVE-2026-33687Sharp is a content management framework built for Laravel as…8.8
- CVE-2026-33688WWBN AVideo is an open source video platform. In versions up…5.3
- CVE-2026-33689xrdp is an open source RDP server. Versions through 0.10.5 h…9.1
- CVE-2026-3369The Better Find and Replace – AI-Powered Suggestions plugin …5.4
Are you affected by CVE-2026-33684?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
