← Back to CVE search

CVE-2026-34733

AVideo

Description

WWBN AVideo is an open source video platform. In versions 26.0 and prior, the AVideo installation script install/deleteSystemdPrivate.php contains a PHP operator precedence bug in its CLI-only access guard. The script is intended to run exclusively from the command line, but the guard condition !php_sapi_name() === -cli- never evaluates to true due to how PHP resolves operator precedence. The ! (logical NOT) operator binds more tightly than === (strict comparison), causing the expression to always evaluate to false, which means the die() statement never executes. As a result, the script is accessible via HTTP without authentication and will delete files from the server-s temp directory while also disclosing the temp directory contents in its response. At time of publication, there are no publicly available patches.

CVSS 6.5EPSS 0.34099999999999997%Risk 0.67
View source
Published
2026-03-31 21:16:32
Affected versions
<=26.0
Type
Core software
Last modified
2026-07-24 20:10:00
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L