CVE-2026-33688: AVideo has Pre-Captcha User Enumeration and Account Status Disclosure in Password Recovery Endpoint
The password recovery endpoint at objects/userRecoverPass.php performs user existence and account status checks before validating the captcha. This allows an unauthenticated attacker to enumerate valid usernames and determine whether accounts are active, inactive, or banned — at scale and without solving any captcha — by observing three distinct JSON error responses.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-33688 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →