Skip to content

Menu
  • Home
Menu

CVE-2026-84479 – WWBN AVideo Authentication Bypass via User-Agent Header

Posted on September 2, 2026
CVE ID :CVE-2026-84479

Published : Sept. 1, 2026, 11:17 p.m. | 1 hour, 19 minutes ago

Description :WWBN AVideo (current e01e41ecc and earlier) makes three login-time security controls depend solely on the client-supplied User-Agent header. The isAVideoEncoder()/isAVideoMobileApp() checks match HTTP_USER_AGENT against a hardcoded literal (“AVideoEncoder”/”AVideoMobileApp”) with no IP check or shared secret. An attacker who submits valid credentials and sets User-Agent: AVideoEncoder bypasses two-factor authentication, skips brute-force captcha escalation, and avoids being recorded in the login/device audit history. No patch is available at the time of publication.

Severity: 9.3 | CRITICAL

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

Post Views: 2

Site map

  • About Us
  • Privacy Policy
  • Terms & Conditions of Use
©2026 | Design: Newspaperly WordPress Theme