Authentication Bypass Vulnerability in WWBN AVideo Product
CVE-2026-84479
9.3CRITICAL
What is CVE-2026-84479?
The WWBN AVideo product has a critical vulnerability where key security controls during login rely exclusively on the User-Agent header provided by the client. This flaw allows attackers, upon entering valid credentials, to manipulate the User-Agent value to 'AVideoEncoder' or 'AVideoMobileApp'. As a consequence, they can bypass essential security measures such as two-factor authentication and the brute-force CAPTCHA protection meant to secure the login process. Moreover, the login attempt will evade recording in the audit history, potentially allowing undetected unauthorized access. This vulnerability is present in all versions up to and including e01e41ecc. No patch is available currently, exposing users to risks.
Affected Version(s)
AVideo 0 <= 29.0
