CVE-2026-33692: CWE-20: Improper Input Validation in WWBN AVideo
WWBN AVideo versions prior to 29.0 have a vulnerability where the .env file is exposed to unauthenticated users due to the official Docker compose configuration mounting the project root as the Apache document root. This exposure allows attackers to access sensitive information such as database credentials and admin passwords. The issue is resolved in version 29.0.
AI Analysis
Technical Summary
WWBN AVideo is an open source video platform. Versions before 29.0 improperly expose the .env file through the official Docker compose setup because the docker-compose.yml mounts the entire project root as the Apache document root. This configuration serves the .env file as a static file at the web root without any .htaccess or Apache rules to block access to dotfiles. The .env file contains sensitive data including database credentials, admin passwords, and infrastructure configuration. Exploiting this vulnerability can lead to direct database access, admin panel takeover, and lateral movement within the Docker network. The vulnerability is fixed in version 29.0.
Potential Impact
Exposure of the .env file allows unauthenticated attackers to obtain sensitive credentials and configuration details. This can lead to unauthorized database access, compromise of the admin panel, and further lateral movement within the Docker network, potentially resulting in a full system compromise.
Mitigation Recommendations
Upgrade to WWBN AVideo version 29.0 or later, where this issue is resolved. The fix involves changing the Docker compose configuration to prevent the .env file from being served publicly. Until upgrading, restrict access to the .env file by modifying the Apache configuration or docker-compose setup to block access to dotfiles.
CVE-2026-33692: CWE-20: Improper Input Validation in WWBN AVideo
Description
WWBN AVideo versions prior to 29.0 have a vulnerability where the .env file is exposed to unauthenticated users due to the official Docker compose configuration mounting the project root as the Apache document root. This exposure allows attackers to access sensitive information such as database credentials and admin passwords. The issue is resolved in version 29.0.
CVSS v3.1
Score 7.5high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
WWBN AVideo is an open source video platform. Versions before 29.0 improperly expose the .env file through the official Docker compose setup because the docker-compose.yml mounts the entire project root as the Apache document root. This configuration serves the .env file as a static file at the web root without any .htaccess or Apache rules to block access to dotfiles. The .env file contains sensitive data including database credentials, admin passwords, and infrastructure configuration. Exploiting this vulnerability can lead to direct database access, admin panel takeover, and lateral movement within the Docker network. The vulnerability is fixed in version 29.0.
Potential Impact
Exposure of the .env file allows unauthenticated attackers to obtain sensitive credentials and configuration details. This can lead to unauthorized database access, compromise of the admin panel, and further lateral movement within the Docker network, potentially resulting in a full system compromise.
Mitigation Recommendations
Upgrade to WWBN AVideo version 29.0 or later, where this issue is resolved. The fix involves changing the Docker compose configuration to prevent the .env file from being served publicly. Until upgrading, restrict access to the .env file by modifying the Apache configuration or docker-compose setup to block access to dotfiles.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-03-23T16:34:59.932Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a59439468715ace43af3f44
Added to database: 07/16/2026, 20:48:20 UTC
Last enriched: 07/23/2026, 22:47:15 UTC
Last updated: 08/30/2026, 22:52:10 UTC
Views: 90
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.