Improper Authentication Vulnerability in Studio-Saelix Sencho Login Endpoint
CVE-2026-108522
Key Information:
- Vendor
Studio-saelix
- Status
- Vendor
- CVE Published:
- 11 October 2026
Badges
What is CVE-2026-108522?
A vulnerability has been identified in Studio-Saelix Sencho versions up to 0.94.1, specifically affecting the Login Endpoint at /api/auth/login. The flaw allows a remote attacker to manipulate the X-Forwarded-For header, leading to improper authentication. This was due to the login limiter's reliance on client-supplied data without an explicit trusted-proxy boundary, enabling the attacker to spoof the originating client address. The recommended solution involves applying a patch that disregards forwarding headers by default, permitting them only from pre-configured proxy CIDRs, and implementing a distinct limit on failed login attempts based on normalized account identities.
Affected Version(s)
Sencho 0.94.0
Sencho 0.94.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
