CVE-2026-86186
published 2026-09-05CVE-2026-86186: AVideo API fails to enforce rate limits when clients send a bot User-Agent header, allowing attackers to bypass all eight protected operations including login…
PriorityP342medium6.5CVSS 3.1
AVNACLPRNUINSUCLILAN
EPSS
0.30%
20.8th percentile
AVideo API fails to enforce rate limits when clients send a bot User-Agent header, allowing attackers to bypass all eight protected operations including login brute-force protection. Attackers can send requests with a bot User-Agent to disable rate limiting and perform unlimited password guessing attempts against any account from a single IP address.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| wwbn | avideo | <= 29.0 | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
nvdv4.06.3MEDIUMCVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
WWBN AVideo up to 29.0 API access control
vuldb·2026-09-05·CVSS 6.5
CVE-2026-86186 [MEDIUM] WWBN AVideo up to 29.0 API access control
A vulnerability identified as critical has been detected in WWBN AVideo up to 29.0. This impacts an unknown function of the component API. This manipulation causes improper access controls.
This vulnerability is handled as CVE-2026-86186. The attack can be initiated remotely. There is not any exploit available.
GHSA
AVideo API fails to enforce rate limits when clients send a bot User-Agent header, allowing attackers to bypass all eight protected operations including login brute-force protection.
ghsa_unreviewed·2026-09-05
CVE-2026-86186 [MEDIUM] CWE-307 AVideo API fails to enforce rate limits when clients send a bot User-Agent header, allowing attackers to bypass all eight protected operations including login brute-force protection.
AVideo API fails to enforce rate limits when clients send a bot User-Agent header, allowing attackers to bypass all eight protected operations including login brute-force protection. Attackers can send requests with a bot User-Agent to disable rate limiting and perform unlimited password guessing attempts against any account from a single IP address.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-09-05
Published