CVE-2026-33692
WWBN AVideo
WWBN AVideo is an open source video platform. Versions prior to 29.0 expose .env files to unauthenticated users through the official Docker compose configuration. The official docker-compose.yml mounts the entire project root directory as the Apache document root, causing the .env file — which contains database credentials, admin passwords, and infrastructure configuration — to be served as a static file at /.env. No .htaccess rule or Apache configuration blocks access to dotfiles. Exploitation enables direct database access, admin panel takeover, and further lateral movement within the Doc...
- CVSS
- 7.5
- EPSS
- 0.27% 18.4% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.17