Authentication Bypass in WWBN AVideo Due to Insufficient Header Validation
CVE-2026-84476
8.7HIGH
What is CVE-2026-84476?
The WWBN AVideo platform contains a vulnerability that arises from a failure to properly validate trusted proxies before processing the X-Real-IP and X-Forwarded-For headers. This oversight enables attackers to spoof client IP addresses, allowing them to bypass protections such as login rate limiting. By manipulating the header values with each request, attackers can execute unlimited credential guessing attempts, posing a significant threat to account security and the integrity of the application.
Affected Version(s)
AVideo 0 <= 29.0
