CVE-2026-33649
HIGH
NVD
CVSS Score
8.1
Severity
HIGH
Published
Mar 23, 2026
Vendor
unknown
Description
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `plugin/Permissions/setPermission.json.php` endpoint accepts GET parameters for a state-changing operation that modifies user group permissions. The endpoint has no CSRF token validation, and the application explicitly sets `session.cookie_samesite=None` on session cookies. This allows an unauthenticated attacker to craft a page with `<img>` tags that, when visited by an admin, silently grant arbitrary permissions to the attacker's user group โ escalating the attacker to near-admin access. As of time of publication, no known patched versions are available.