#VU125478 Improper Restriction of Excessive Authentication Attempts in AVideo - CVE-2026-33763

 

#VU125478 Improper Restriction of Excessive Authentication Attempts in AVideo - CVE-2026-33763

Published: April 8, 2026


Vulnerability identifier: #VU125478
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2026-33763
CWE-ID: CWE-307
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
AVideo
Software vendor:
World Wide Broadcast Network

Description

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper restriction of excessive authentication attempts in the get_api_video_password_is_correct API endpoint when handling password-verification requests for password-protected videos. A remote attacker can send repeated password guesses and use the boolean passwordIsCorrect response to disclose sensitive information.

The endpoint is reachable without authentication and requires no user interaction.


Remediation

Install security update from vendor's website.

External links