Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 02 Sep 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 01 Sep 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | WWBN AVideo (current e01e41ecc and earlier) makes three login-time security controls depend solely on the client-supplied User-Agent header. The isAVideoEncoder()/isAVideoMobileApp() checks match HTTP_USER_AGENT against a hardcoded literal ("AVideoEncoder"/"AVideoMobileApp") with no IP check or shared secret. An attacker who submits valid credentials and sets User-Agent: AVideoEncoder bypasses two-factor authentication, skips brute-force captcha escalation, and avoids being recorded in the login/device audit history. No patch is available at the time of publication. | |
| Title | WWBN AVideo Authentication Bypass via User-Agent Header | |
| First Time appeared |
Wwbn
Wwbn avideo |
|
| Weaknesses | CWE-290 | |
| CPEs | cpe:2.3:a:wwbn:avideo:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Wwbn
Wwbn avideo |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-02T11:43:24.854Z
Reserved: 2026-09-01T20:37:00.841Z
Link: CVE-2026-84479
Updated: 2026-09-02T11:41:22.593Z
Status : Received
Published: 2026-09-01T23:17:22.083
Modified: 2026-09-02T12:17:14.160
Link: CVE-2026-84479
No data.
OpenCVE Enrichment
Updated: 2026-09-02T00:30:03Z
