CVE-2026-84476: WWBN AVideo Authentication Bypass via X-Real-IP Header

Published Sep 1, 2026
·
Updated

WWBN AVideo fails to validate trusted proxies before accepting X-Real-IP and X-Forwarded-For headers, allowing attackers to spoof the client address used by enforceRateLimit(). Attackers can rotate the header value per request to bypass login rate limiting and perform unlimited credential guessing attacks.

Affected Software

1 affected component
AVideo

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Compensating control

    Ensure WWBN AVideo validates trusted proxies before accepting the X-Real-IP and X-Forwarded-For headers; only honor client IP from these headers when the request originates from a configured trusted proxy.

Event History

Sep 1, 2026
CVE Published
via MITRE·10:25 PM
Data Sourced
via MITRE·10:25 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

AVideo instances that accept attacker-controlled X-Real-IP or X-Forwarded-For headers for client address determination are exposed. The issue is reachable remotely and does not require authentication or user interaction.

2

What does an attacker need to bypass the login rate limit?

An attacker can send login requests with spoofed X-Real-IP or X-Forwarded-For values and change the value on each request. This causes enforceRateLimit() to treat credential-guessing attempts as coming from different client addresses.

3

What is the practical impact?

The bypass permits unlimited credential guessing attempts against the login functionality despite rate limiting. The provided severity vector indicates high confidentiality impact, with no stated integrity or availability impact.

4

What can be changed if patching is not immediately possible?

Ensure AVideo only accepts client-IP forwarding headers from validated, trusted proxies, and prevent direct clients from supplying X-Real-IP or X-Forwarded-For values that influence rate limiting.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203