CVE-2026-33043

8.1

WWBN · AVideo

WWBN AVideo contains a permissive cross-domain policy vulnerability that allows unauthenticated attackers to perform cross-origin session theft and full account takeover.

Executive summary

A critical vulnerability in WWBN AVideo allows unauthenticated attackers to hijack user sessions and perform full account takeovers via cross-origin exploitation.

Vulnerability

The application utilizes an insecure allowOrigin function that reflects arbitrary Origin headers with credentials enabled, and it exposes session identifiers via an unauthenticated endpoint. This combination allows an unauthenticated attacker to steal session tokens from legitimate users, leading to unauthorized account access.

Business impact

Successful exploitation results in full account takeover, which can lead to the unauthorized access of sensitive video content, user data, and administrative functionality. Given the CVSS score of 8.1, this vulnerability represents a high risk to organizational security, potentially resulting in severe reputational damage and the compromise of protected intellectual property.

Remediation

Immediate Action: Upgrade to WWBN AVideo version 26.0 or later immediately to resolve the insecure cross-domain policy and session exposure.

Proactive Monitoring: Review web server access logs for anomalous cross-origin requests and monitor user session patterns for suspicious login behavior or unauthorized account modifications.

Compensating Controls: Implement a strict Content Security Policy (CSP) and ensure the Web Application Firewall (WAF) is configured to block requests that contain malicious or unauthorized Origin headers.

Exploitation status

Public Exploit Available: No (There is no confirmed weaponized exploit or public proof-of-concept repository available).

Analyst recommendation

The severity of this vulnerability, combined with the potential for complete account takeover, necessitates immediate attention. Administrators must prioritize updating the AVideo platform to version 26.0 to eliminate the underlying flaw. Failure to apply this update leaves the environment vulnerable to session theft and unauthorized administrative access.

More WWBN CVEs

Sources