CVE-2026-108522: Studio-Saelix Sencho Login Endpoint login improper authentication

Published Oct 11, 2026
·
Updated

A vulnerability was found in Studio-Saelix Sencho up to 0.94.1. This affects an unknown part of the file /api/auth/login of the component Login Endpoint. Performing a manipulation of the argument X-Forwarded-For results in improper authentication. The attack is possible to be carried out remotely. The exploit has been made public and could be used. The patch is named 79b86ddcd4aefdd6941f098e35990ab397b13c72. To fix this issue, it is recommended to deploy a patch. The vendor confirms: "The login limiter relied on client-supplied X-Forwarded-For data without an explicit trusted-proxy boundary, allowing an attacker to rotate the apparent client address. The remediation now ignores forwarding headers by default, accepts them only from explicitly configured proxy CIDRs, and adds a separate failed-attempt limit keyed by normalized account identity."

Affected Software

1 affected component
Studio-Saelix Sencho<=0.94.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Patch 79b86ddcd4aefdd6941f098e35990ab397b13c72
  2. Configuration

    Configure the login endpoint to ignore forwarding headers by default and trust them only when requests originate from explicitly configured proxy CIDRs.

    Login Endpoint trusted proxy CIDRs and forwarding headers = Ignore forwarding headers by default; accept them only from explicitly configured proxy CIDRs
  3. Configuration

    Add or enable a separate failed-attempt limit keyed by normalized account identity.

    Login Endpoint failed-attempt limiting = Key by normalized account identity

Event History

Oct 11, 2026
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:17 AM
DescriptionSeverityWeakness
Event
via NVD·05:40 AM

Frequently Asked Questions

1

What attacker access is required to exploit this issue?

An attacker can exploit the issue remotely with no privileges or user interaction required. The public exploit means attempted exploitation should be considered feasible.

2

How does the authentication control get bypassed?

The login limiter trusted the client-supplied X-Forwarded-For header without an explicit trusted-proxy boundary. An attacker can rotate the apparent client IP address to evade IP-based failed-login limiting.

3

Are deployments without a configured reverse proxy affected?

The affected behavior is reliance on X-Forwarded-For data without an explicit trusted-proxy boundary. The remediation ignores forwarding headers by default and accepts them only from explicitly configured proxy CIDRs.

4

What should be done if patching cannot happen immediately?

Do not trust client-supplied forwarding headers at the login endpoint, and ensure such headers are accepted only from explicitly configured proxy CIDRs. Apply a separate failed-attempt limit keyed to normalized account identity where possible.

5

Which versions need remediation?

Studio-Saelix Sencho versions up to 0.94.1 are affected. The available patch is commit 79b86ddcd4aefdd6941f098e35990ab397b13c72.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203