Description
AVideo API fails to enforce rate limits when clients send a bot User-Agent header, allowing attackers to bypass all eight protected operations including login brute-force protection. Attackers can send requests with a bot User-Agent to disable rate limiting and perform unlimited password guessing attempts against any account from a single IP address.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Sat, 05 Sep 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | AVideo API fails to enforce rate limits when clients send a bot User-Agent header, allowing attackers to bypass all eight protected operations including login brute-force protection. Attackers can send requests with a bot User-Agent to disable rate limiting and perform unlimited password guessing attempts against any account from a single IP address. | |
| Title | AVideo API Rate Limit Bypass via Bot User-Agent Header | |
| First Time appeared |
Wwbn
Wwbn avideo |
|
| Weaknesses | CWE-307 | |
| CPEs | cpe:2.3:a:wwbn:avideo:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Wwbn
Wwbn avideo |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-05T12:09:02.729Z
Reserved: 2026-09-05T11:51:31.101Z
Link: CVE-2026-86186
No data.
Status : Received
Published: 2026-09-05T13:18:13.560
Modified: 2026-09-05T13:18:13.560
Link: CVE-2026-86186
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-307
Improper Restriction of Excessive Authentication Attempts