CVE-2026-84476
WWBN AVideo fails to validate trusted proxies before accepting X-Real-IP and X-Forwarded-For headers, allowing attackers to spoof the client address used by enforceRateLimit(). Attackers can rotate the header value per request to bypass login rate limiting and perform unlimited credential guessing attacks.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.7
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.26%
- CWE
- CWE-290
- Published
- 2026-09-01
- Last modified
- 2026-09-02
Affected products
- WWBN AVideo
Weakness type
Related vulnerabilities
- CVE-2026-82563 — Softish C6 Ear Camera and EarVision Android Application Authentication bypass by spoofing
- CVE-2026-82530 — IP2Location Country Blocker < 2.45.0 Access Control Bypass via X-Real-IP Header
- CVE-2026-62759 — Windows Netlogon Spoofing Vulnerability
- CVE-2026-86478 — In JetBrains YouTrack before 2025.3.161254,...
- CVE-2026-84186 — Incorrect access control in PrestaShop
- CVE-2026-86196 — Grav API Plugin before 1.0.20 Authentication Bypass via Host Header
- CVE-2026-85432 — MOOS core-moos through 10.4.0 MOOSDB Message Source Spoofing via Wire Identity
- CVE-2026-84766 — WordPress FluentBooking Pro plugin <= 2.2.1 - Bypass Vulnerability vulnerability