#VU125478 Improper Restriction of Excessive Authentication Attempts in AVideo - CVE-2026-33763
Published: April 8, 2026
AVideo
World Wide Broadcast Network
Description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper restriction of excessive authentication attempts in the get_api_video_password_is_correct API endpoint when handling password-verification requests for password-protected videos. A remote attacker can send repeated password guesses and use the boolean passwordIsCorrect response to disclose sensitive information.
The endpoint is reachable without authentication and requires no user interaction.