Device Registration Glitch in Remnawave Proxy Management Solution
CVE-2026-39880

5MEDIUM

Key Information:

Vendor

Remnawave

Status
Vendor
CVE Published:
8 April 2026

What is CVE-2026-39880?

The Remnawave Backend, integral to the Remnawave proxy and user management system, contains a flaw in its HWID device registration logic prior to version 2.7.5. This vulnerability allows an authenticated user to exceed the preset limit on HWID devices, enabling them to register more devices than intended. Consequently, this could lead to unauthorized subscription reselling and excessive traffic consumption, potentially affecting the performance and security of the service.

Affected Version(s)

backend < 2.7.5

References

CVSS V3.1

Score:
5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.