CVE-2026-108522: Studio-Saelix Sencho Login Endpoint login improper authentication
A vulnerability was found in Studio-Saelix Sencho up to 0.94.1. This affects an unknown part of the file /api/auth/login of the component Login Endpoint. Performing a manipulation of the argument X-Forwarded-For results in improper authentication. The attack is possible to be carried out remotely. The exploit has been made public and could be used. The patch is named 79b86ddcd4aefdd6941f098e35990ab397b13c72. To fix this issue, it is recommended to deploy a patch. The vendor confirms: "The login limiter relied on client-supplied X-Forwarded-For data without an explicit trusted-proxy boundary, allowing an attacker to rotate the apparent client address. The remediation now ignores forwarding headers by default, accepts them only from explicitly configured proxy CIDRs, and adds a separate failed-attempt limit keyed by normalized account identity."
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch 79b86ddcd4aefdd6941f098e35990ab397b13c72 - Configuration
Configure the login endpoint to ignore forwarding headers by default and trust them only when requests originate from explicitly configured proxy CIDRs.
Login Endpoint trusted proxy CIDRs and forwarding headers = Ignore forwarding headers by default; accept them only from explicitly configured proxy CIDRs - Configuration
Add or enable a separate failed-attempt limit keyed by normalized account identity.
Login Endpoint failed-attempt limiting = Key by normalized account identity
Event History
Frequently Asked Questions
What attacker access is required to exploit this issue?
An attacker can exploit the issue remotely with no privileges or user interaction required. The public exploit means attempted exploitation should be considered feasible.
How does the authentication control get bypassed?
The login limiter trusted the client-supplied X-Forwarded-For header without an explicit trusted-proxy boundary. An attacker can rotate the apparent client IP address to evade IP-based failed-login limiting.
Are deployments without a configured reverse proxy affected?
The affected behavior is reliance on X-Forwarded-For data without an explicit trusted-proxy boundary. The remediation ignores forwarding headers by default and accepts them only from explicitly configured proxy CIDRs.
What should be done if patching cannot happen immediately?
Do not trust client-supplied forwarding headers at the login endpoint, and ensure such headers are accepted only from explicitly configured proxy CIDRs. Apply a separate failed-attempt limit keyed to normalized account identity where possible.
Which versions need remediation?
Studio-Saelix Sencho versions up to 0.94.1 are affected. The available patch is commit 79b86ddcd4aefdd6941f098e35990ab397b13c72.