Device Registration Glitch in Remnawave Proxy Management Solution
CVE-2026-39880
5MEDIUM
What is CVE-2026-39880?
The Remnawave Backend, integral to the Remnawave proxy and user management system, contains a flaw in its HWID device registration logic prior to version 2.7.5. This vulnerability allows an authenticated user to exceed the preset limit on HWID devices, enabling them to register more devices than intended. Consequently, this could lead to unauthorized subscription reselling and excessive traffic consumption, potentially affecting the performance and security of the service.
Affected Version(s)
backend < 2.7.5
