Loading market data...
← Back to CVE feed

CVE-2026-84476

HIGH CVSS 7.5 View on NVD ↗

Description

WWBN AVideo fails to validate trusted proxies before accepting X-Real-IP and X-Forwarded-For headers, allowing attackers to spoof the client address used by enforceRateLimit(). Attackers can rotate the header value per request to bypass login rate limiting and perform unlimited credential guessing attacks.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Published: Sep 01, 2026 23:17 UTC Modified: Sep 02, 2026 13:18 UTC