Authentication Bypass Vulnerability in WWBN AVideo Product
CVE-2026-84479

9.3CRITICAL

Key Information:

Vendor

Wwbn

Status
Vendor
CVE Published:
1 September 2026

What is CVE-2026-84479?

The WWBN AVideo product has a critical vulnerability where key security controls during login rely exclusively on the User-Agent header provided by the client. This flaw allows attackers, upon entering valid credentials, to manipulate the User-Agent value to 'AVideoEncoder' or 'AVideoMobileApp'. As a consequence, they can bypass essential security measures such as two-factor authentication and the brute-force CAPTCHA protection meant to secure the login process. Moreover, the login attempt will evade recording in the audit history, potentially allowing undetected unauthorized access. This vulnerability is present in all versions up to and including e01e41ecc. No patch is available currently, exposing users to risks.

Affected Version(s)

AVideo 0 <= 29.0

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

rajivraj
.