CVE-2026-33763 | WWBN AVideo up to 26.0 API Endpoint get_api_video_password_is_correct passwordIsCorrect excessive authentication
VulDBArchived Mar 27, 2026✓ Full text saved
A vulnerability classified as problematic has been found in WWBN AVideo up to 26.0 . Impacted is the function get_api_video_password_is_correct of the component API Endpoint . Performing a manipulation of the argument passwordIsCorrect results in improper restriction of excessive authentication attempts. This vulnerability is cataloged as CVE-2026-33763 . It is possible to initiate the attack remotely. There is no exploit available. It is recommended to apply a patch to fix this issue.
Full text archived locally
✦ AI Summary· Claude Sonnet
VDB-353920 · CVE-2026-33763 · GCVE-0-2026-33763
WWBN AVIDEO UP TO 26.0 API ENDPOINT GET_API_VIDEO_PASSWORD_IS_CORRECT PASSWORDISCORRECT EXCESSIVE AUTHENTICATION
HISTORYDIFFRELATEJSONXMLCTI
CVSS Meta Temp Score Current Exploit Price (≈) CTI Interest Score
5.2 $0-$5k 0.73+
Summaryinfo
A vulnerability classified as problematic was found in WWBN AVideo up to 26.0. The affected element is the function get_api_video_password_is_correct of the component API Endpoint. Executing a manipulation of the argument passwordIsCorrect can lead to excessive authentication. This vulnerability is registered as CVE-2026-33763. It is possible to launch the attack remotely. No exploit is available. Applying a patch is advised to resolve this issue.
Detailsinfo
A vulnerability has been found in WWBN AVideo up to 26.0 and classified as problematic. This vulnerability affects the function get_api_video_password_is_correct of the component API Endpoint. The manipulation of the argument passwordIsCorrect with an unknown input leads to a excessive authentication vulnerability. The CWE definition for the vulnerability is CWE-307. The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it more susceptible to brute force attacks. As an impact it is known to affect confidentiality. CVE summarizes:
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `get_api_video_password_is_correct` API endpoint allows any unauthenticated user to verify whether a given password is correct for any password-protected video. The endpoint returns a boolean `passwordIsCorrect` field with no rate limiting, CAPTCHA, or authentication requirement, enabling efficient offline-speed brute-force attacks against video passwords. Commit 01a0614fedcdaee47832c0d913a0fb86d8c28135 contains a patch.
The advisory is shared for download at github.com. This vulnerability was named CVE-2026-33763 since 03/23/2026. The exploitation appears to be easy. The attack can be initiated remotely. No form of authentication is required for a successful exploitation. There are known technical details, but no exploit is available. The MITRE ATT&CK project declares the attack technique as T1110.001.
Applying a patch is able to eliminate this problem.
Productinfo
Vendor
WWBN
Name
AVideo
Version
26.0
License
open-source
Website
Product: https://github.com/WWBN/AVideo/
CPE 2.3info
🔒
CPE 2.2info
🔒
CVSSv4info
VulDB Vector: 🔒
VulDB Reliability: 🔍
CVSSv3info
VulDB Meta Base Score: 5.3
VulDB Meta Temp Score: 5.2
VulDB Base Score: 5.3
VulDB Temp Score: 5.1
VulDB Vector: 🔒
VulDB Reliability: 🔍
CNA Base Score: 5.3
CNA Vector (GitHub_M): 🔒
CVSSv2info
Vector Complexity Authentication Confidentiality Integrity Availability
Unlock Unlock Unlock Unlock Unlock Unlock
Unlock Unlock Unlock Unlock Unlock Unlock
Unlock Unlock Unlock Unlock Unlock Unlock
VulDB Base Score: 🔒
VulDB Temp Score: 🔒
VulDB Reliability: 🔍
Exploitinginfo
Class: Excessive authentication
CWE: CWE-307 / CWE-799 / CWE-400
CAPEC: 🔒
ATT&CK: 🔒
Physical: No
Local: No
Remote: Yes
Availability: 🔒
Status: Not defined
Price Prediction: 🔍
Current Price Estimation: 🔒
0-Day Unlock Unlock Unlock Unlock
Today Unlock Unlock Unlock Unlock
Threat Intelligenceinfo
Interest: 🔍
Active Actors: 🔍
Active APT Groups: 🔍
Countermeasuresinfo
Recommended: Patch
Status: 🔍
0-Day Time: 🔒
Timelineinfo
03/23/2026 CVE reserved
03/27/2026 +4 days Advisory disclosed
03/27/2026 +0 days VulDB entry created
03/27/2026 +0 days VulDB entry last update
Sourcesinfo
Product: github.com
Advisory: github.com
Status: Confirmed
CVE: CVE-2026-33763 (🔒)
GCVE (CVE): GCVE-0-2026-33763
GCVE (VulDB): GCVE-100-353920
Entryinfo
Created: 03/27/2026 15:47
Changes: 03/27/2026 15:47 (65)
Complete: 🔍
Cache ID: 99:E04:101
Discussion
No comments yet. Languages: en.
Please log in to comment.
◂ PreviousOverviewNext ▸