CVE-2026-33037 - Vulnerability Analysis
HighCVSS: 8.1Last Updated: March 20, 2026
WWBN AVideo - Authentication Bypass
Published: March 20, 2026Updated: March 20, 2026Remote Exploitable
Overview
WWBN AVideo <= 25.0 contains a broken authentication caused by default weak admin and database passwords in Docker deployment files, letting attackers gain full admin access, exploit requires default passwords unchanged.
Severity & Score
Severity: High
CVSS Score: 8.1
Impact
Attackers can gain full admin access, exposing user data, manipulating content, and potentially executing remote code.
Mitigation
Update to version 26.0 or later and change default passwords.
References
Related Resources
Details
- CVE ID
- CVE-2026-33037
- Severity
- High
- CVSS Score
- 8.1
- Type
- broken_authentication
- Status
- new
CWE
- CWE-1188
CVSS Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H