Authentication Bypass in WWBN AVideo Due to Insufficient Header Validation
CVE-2026-84476

8.7HIGH

Key Information:

Vendor

Wwbn

Status
Vendor
CVE Published:
1 September 2026

What is CVE-2026-84476?

The WWBN AVideo platform contains a vulnerability that arises from a failure to properly validate trusted proxies before processing the X-Real-IP and X-Forwarded-For headers. This oversight enables attackers to spoof client IP addresses, allowing them to bypass protections such as login rate limiting. By manipulating the header values with each request, attackers can execute unlimited credential guessing attempts, posing a significant threat to account security and the integrity of the application.

Affected Version(s)

AVideo 0 <= 29.0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

rajivraj
.