CVE-2026-108580: AniWorld Downloader before 5.3.0 WebUI Login Brute Force via /login
AniWorld Downloader before 5.3.0 contains an improper restriction of authentication attempts vulnerability in the WebUI /login POST handler that allows unauthenticated attackers to guess passwords without throttling. Attackers can enumerate usernames through verifyuser response timing and brute-force passwords on exposed WebUI instances to take over accounts.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
AniWorld Downloaderto a version that resolves this vulnerability.Fixed in 5.3.0
Event History
Frequently Asked Questions
Which deployments are exposed?
AniWorld Downloader WebUI instances exposed to attackers are affected when running versions before 5.3.0.
Does an attacker need an existing account to attempt exploitation?
No. The vulnerable /login handler can be targeted by unauthenticated attackers, who can enumerate usernames through response timing and repeatedly guess passwords without throttling.
What version should be used to address the issue?
Upgrade AniWorld Downloader to version 5.3.0 or later.