CVE-2026-86729
Deferred Deferred - Pending Action

Unauthenticated Brute-Force in AVideo

Vulnerability report for CVE-2026-86729, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-10

Assigner: VulnCheck

Description

WWBN AVideo through commit e01e41ecc (no patched version available) exposes get_api_preauthorize in plugin/API/API.php as a second, undocumented login path. Unlike get_api_signIn, which enforces a rate limit of 10 attempts per 5 minutes via checkRateLimit(), get_api_preauthorize performs the same credential check with no throttling for any client, allowing unlimited remote password guessing against arbitrary accounts, including admin. The endpoint also acts as a credential oracle: it returns the message "Invalid credentials" for both correct and incorrect passwords, while the users_id field in the response body discloses the authenticated identity (users_id:1 on success, users_id:0 on failure), and a correct password establishes a session cookie that remains usable for authenticated API requests. Together these issues permit unauthenticated brute-force account takeover.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-10
Generated
2026-09-29
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wwbn avideo *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-307 The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in WWBN AVideo allows unauthenticated attackers to perform unlimited password guessing attacks against any account, including admin accounts. The flaw exists in an undocumented login endpoint called get_api_preauthorize, which lacks rate limiting unlike the official login method. It also acts as a credential oracle by revealing valid usernames through response fields and establishes authenticated sessions upon successful login.

Detection Guidance

Check for unusual API login attempts to the undocumented get_api_preauthorize endpoint. Monitor for high volumes of requests to this path without rate limiting. Inspect responses for users_id field in the body, which indicates success (users_id:1) or failure (users_id:0).

Commands: Use curl to test the endpoint: curl -X POST 'http://<target>/plugin/API/API.php?do=preauthorize&user=<username>&pass=<password>'. Check server logs for repeated failed attempts to this endpoint.

Impact Analysis

Attackers could exploit this to take over any account, including admin accounts, by guessing passwords without restriction. Once an account is compromised, attackers gain access to sensitive data and system functions. The vulnerability also allows enumeration of valid usernames, making targeted attacks easier.

Mitigation Strategies

Disable or restrict access to the get_api_preauthorize endpoint immediately. Implement rate limiting on all login endpoints, including this one. Update to a patched version if available. Monitor for unauthorized session cookies or brute-force attempts.

If no patch exists, consider blocking the endpoint via firewall rules or web server configuration until a fix is released.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-86729. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart