Common Weakness Enumeration

CWE-307

Allowed

Improper Restriction of Excessive Authentication Attempts

Abstraction: Base · Status: Draft

The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.

1024 vulnerabilities reference this CWE, most recent first.

CVE-2026-102825 (GCVE-0-2026-102825)

Vulnerability from cvelistv5 – Published: 2026-09-29 18:31 – Updated: 2026-09-30 19:29
VLAI
Title
Russh: Configured server auth-attempt cap is not enforced in the USERAUTH_REQUEST runtime path
Summary
Russh is a Rust SSH client and server library. Prior to 0.62.6, the USERAUTH_REQUEST path reached from server::run_stream in russh/src/server/encrypted.rs increments self.common.auth_attempts but never compares it with server::Config.max_auth_attempts. An unauthenticated remote client can continue submitting authentication requests on one connection beyond the configured cap, bypassing the deployment's attempt-limiting policy and increasing online guessing opportunity and backend authentication workload. This issue is fixed in version 0.62.6.
SSVC
Exploitation: poc Automatable: no Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-30 19:29 UTC
CWE
  • CWE-307 - Improper Restriction of Excessive Authentication Attempts
Impacted products
Vendor Product Version
Eugeny russh Affected: < 0.62.6
Create a notification for this product.
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-102825",
                "options": [
                  {
                    "Exploitation": "poc"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-09-30T19:29:11.461462Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-09-30T19:29:26.432Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "references": [
          {
            "tags": [
              "exploit"
            ],
            "url": "https://github.com/Eugeny/russh/security/advisories/GHSA-g6xm-f9xp-qq35"
          }
        ],
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "product": "russh",
          "vendor": "Eugeny",
          "versions": [
            {
              "status": "affected",
              "version": "\u003c 0.62.6"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "Russh is a Rust SSH client and server library. Prior to 0.62.6, the USERAUTH_REQUEST path reached from server::run_stream in russh/src/server/encrypted.rs increments self.common.auth_attempts but never compares it with server::Config.max_auth_attempts. An unauthenticated remote client can continue submitting authentication requests on one connection beyond the configured cap, bypassing the deployment\u0027s attempt-limiting policy and increasing online guessing opportunity and backend authentication workload. This issue is fixed in version 0.62.6."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 3.7,
            "baseSeverity": "LOW",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          }
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-307",
              "description": "CWE-307: Improper Restriction of Excessive Authentication Attempts",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-09-29T18:31:32.393Z",
        "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "shortName": "GitHub_M"
      },
      "references": [
        {
          "name": "https://github.com/Eugeny/russh/security/advisories/GHSA-g6xm-f9xp-qq35",
          "tags": [
            "x_refsource_CONFIRM"
          ],
          "url": "https://github.com/Eugeny/russh/security/advisories/GHSA-g6xm-f9xp-qq35"
        },
        {
          "name": "https://github.com/Eugeny/russh/commit/f8fd0b11a393364dc7f01a182482d86adafdd653",
          "tags": [
            "x_refsource_MISC"
          ],
          "url": "https://github.com/Eugeny/russh/commit/f8fd0b11a393364dc7f01a182482d86adafdd653"
        },
        {
          "name": "https://github.com/Eugeny/russh/releases/tag/v0.62.6",
          "tags": [
            "x_refsource_MISC"
          ],
          "url": "https://github.com/Eugeny/russh/releases/tag/v0.62.6"
        }
      ],
      "source": {
        "advisory": "GHSA-g6xm-f9xp-qq35",
        "discovery": "UNKNOWN"
      },
      "title": "Russh: Configured server auth-attempt cap is not enforced in the USERAUTH_REQUEST runtime path"
    }
  },
  "cveMetadata": {
    "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
    "assignerShortName": "GitHub_M",
    "cveId": "CVE-2026-102825",
    "datePublished": "2026-09-29T18:31:32.393Z",
    "dateReserved": "2026-09-29T17:25:25.265Z",
    "dateUpdated": "2026-09-30T19:29:26.432Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-102334 (GCVE-0-2026-102334)

Vulnerability from cvelistv5 – Published: 2026-09-28 22:21 – Updated: 2026-09-29 19:47
VLAI
Title
Nginx Proxy Manager through 2.16.0 Missing Brute-Force Protection
Summary
Nginx Proxy Manager through 2.16.0 lacks rate-limiting on authentication endpoints, allowing unauthenticated attackers to make unlimited password guesses against any account. Attackers can brute-force login credentials via POST /api/tokens and subsequently guess TOTP codes via POST /api/tokens/2fa to gain full session access and administrative control.
SSVC
Exploitation: none Automatable: no Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-29 19:47 UTC
CWE
  • CWE-307 - Improper Restriction of Excessive Authentication Attempts
Impacted products
Vendor Product Version
NginxProxyManager nginx-proxy-manager Affected: 0 , ≤ 2.16.0 (custom)
    cpe:2.3:a:nginxproxymanager:nginx_proxy_manager:*:*:*:*:*:*:*:*
Create a notification for this product.
Date Public
2026-09-28 00:00
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-102334",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "total"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-09-29T19:47:02.219168Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-09-29T19:47:25.772Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "packageURL": "pkg:github/NginxProxyManager/nginx-proxy-manager",
          "product": "nginx-proxy-manager",
          "repo": "https://github.com/NginxProxyManager/nginx-proxy-manager",
          "vendor": "NginxProxyManager",
          "versions": [
            {
              "lessThanOrEqual": "2.16.0",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:a:nginxproxymanager:nginx_proxy_manager:*:*:*:*:*:*:*:*",
                  "versionEndIncluding": "2.16.0",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "finder",
          "value": "Lazizbek Djurayev (Haad TC)"
        }
      ],
      "datePublic": "2026-09-28T00:00:00.000Z",
      "descriptions": [
        {
          "lang": "en",
          "value": "Nginx Proxy Manager through 2.16.0 lacks rate-limiting on authentication endpoints, allowing unauthenticated attackers to make unlimited password guesses against any account. Attackers can brute-force login credentials via POST /api/tokens and subsequently guess TOTP codes via POST /api/tokens/2fa to gain full session access and administrative control."
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "attackComplexity": "LOW",
            "attackRequirements": "PRESENT",
            "attackVector": "NETWORK",
            "baseScore": 9.1,
            "baseSeverity": "CRITICAL",
            "privilegesRequired": "NONE",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N",
            "version": "4.0",
            "vulnAvailabilityImpact": "NONE",
            "vulnConfidentialityImpact": "HIGH",
            "vulnIntegrityImpact": "HIGH"
          },
          "format": "CVSS"
        },
        {
          "cvssV3_1": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 7.4,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
            "version": "3.1"
          },
          "format": "CVSS"
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-307",
              "description": "Improper Restriction of Excessive Authentication Attempts",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-09-28T22:21:41.072Z",
        "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "shortName": "VulnCheck"
      },
      "references": [
        {
          "tags": [
            "patch",
            "issue-tracking"
          ],
          "url": "https://github.com/NginxProxyManager/nginx-proxy-manager/pull/5908"
        },
        {
          "tags": [
            "technical-description"
          ],
          "url": "https://github.com/NginxProxyManager/nginx-proxy-manager/blob/v2.16.0/backend/app.js#L15-L58"
        },
        {
          "tags": [
            "technical-description"
          ],
          "url": "https://github.com/NginxProxyManager/nginx-proxy-manager/blob/v2.16.0/backend/internal/token.js#L154-L182"
        },
        {
          "tags": [
            "technical-description"
          ],
          "url": "https://github.com/NginxProxyManager/nginx-proxy-manager/blob/v2.16.0/backend/internal/2fa.js#L196-L240"
        },
        {
          "tags": [
            "product"
          ],
          "url": "https://github.com/NginxProxyManager/nginx-proxy-manager"
        },
        {
          "name": "VulnCheck Advisory: Nginx Proxy Manager through 2.16.0 Missing Brute-Force Protection",
          "tags": [
            "third-party-advisory"
          ],
          "url": "https://www.vulncheck.com/advisories/nginx-proxy-manager-through-2.16.0-missing-brute-force-protection"
        }
      ],
      "title": "Nginx Proxy Manager through 2.16.0 Missing Brute-Force Protection",
      "x_generator": {
        "engine": "vulncheck-endgame"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
    "assignerShortName": "VulnCheck",
    "cveId": "CVE-2026-102334",
    "datePublished": "2026-09-28T22:21:41.072Z",
    "dateReserved": "2026-09-28T22:08:55.547Z",
    "dateUpdated": "2026-09-29T19:47:25.772Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-100678 (GCVE-0-2026-100678)

Vulnerability from cvelistv5 – Published: 2026-09-26 13:23 – Updated: 2026-09-30 15:00
VLAI
Title
stoatchat before 0.15.5 MFA Brute Force via Insufficient Rate Limiting
Summary
stoatchat before 0.15.5 fails to enforce account-level attempt limits on MFA login challenges, allowing attackers who know a password to guess TOTP codes with only IP-based rate limiting. Attackers can reuse MFA challenge tickets across multiple failed attempts and distribute guesses across IP addresses to bypass rate limiting and gain account access.
SSVC
Exploitation: poc Automatable: no Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-30 14:59 UTC
CWE
  • CWE-307 - Improper Restriction of Excessive Authentication Attempts
References
Impacted products
Vendor Product Version
stoatchat stoatchat Affected: 0 , < 0.15.5 (semver)
Unaffected: 0.15.5 (semver)
Create a notification for this product.
Date Public
2026-09-11 00:00
Credits
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-100678",
                "options": [
                  {
                    "Exploitation": "poc"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-09-30T14:59:59.255314Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-09-30T15:00:30.440Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "references": [
          {
            "tags": [
              "exploit"
            ],
            "url": "https://github.com/stoatchat/stoatchat/security/advisories/GHSA-6877-g673-f5r8"
          }
        ],
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "stoatchat",
          "vendor": "stoatchat",
          "versions": [
            {
              "lessThan": "0.15.5",
              "status": "affected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "0.15.5",
              "versionType": "semver"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "reporter",
          "value": "QuentinRa"
        }
      ],
      "datePublic": "2026-09-11T00:00:00.000Z",
      "descriptions": [
        {
          "lang": "en",
          "value": "stoatchat before 0.15.5 fails to enforce account-level attempt limits on MFA login challenges, allowing attackers who know a password to guess TOTP codes with only IP-based rate limiting. Attackers can reuse MFA challenge tickets across multiple failed attempts and distribute guesses across IP addresses to bypass rate limiting and gain account access."
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "attackComplexity": "HIGH",
            "attackRequirements": "PRESENT",
            "attackVector": "NETWORK",
            "baseScore": 8.3,
            "baseSeverity": "HIGH",
            "privilegesRequired": "NONE",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "vectorString": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N",
            "version": "4.0",
            "vulnAvailabilityImpact": "NONE",
            "vulnConfidentialityImpact": "HIGH",
            "vulnIntegrityImpact": "LOW"
          },
          "format": "CVSS"
        },
        {
          "cvssV3_1": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "LOW",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N",
            "version": "3.1"
          },
          "format": "CVSS"
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-307",
              "description": "Improper Restriction of Excessive Authentication Attempts",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-09-26T13:23:40.935Z",
        "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "shortName": "VulnCheck"
      },
      "references": [
        {
          "name": "GitHub Security Advisory (GHSA-6877-g673-f5r8)",
          "tags": [
            "vendor-advisory"
          ],
          "url": "https://github.com/stoatchat/stoatchat/security/advisories/GHSA-6877-g673-f5r8"
        },
        {
          "name": "VulnCheck Advisory: stoatchat before 0.15.5 MFA Brute Force via Insufficient Rate Limiting",
          "tags": [
            "third-party-advisory"
          ],
          "url": "https://www.vulncheck.com/advisories/stoatchat-before-0.15.5-mfa-brute-force-via-insufficient-rate-limiting"
        }
      ],
      "title": "stoatchat before 0.15.5 MFA Brute Force via Insufficient Rate Limiting",
      "x_generator": {
        "engine": "vulncheck-endgame"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
    "assignerShortName": "VulnCheck",
    "cveId": "CVE-2026-100678",
    "datePublished": "2026-09-26T13:23:40.935Z",
    "dateReserved": "2026-09-26T02:36:51.809Z",
    "dateUpdated": "2026-09-30T15:00:30.440Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-100501 (GCVE-0-2026-100501)

Vulnerability from cvelistv5 – Published: 2026-09-25 22:04 – Updated: 2026-09-25 22:04
VLAI
Title
Flame through 2.4.0 Brute-Force Attack via Login Endpoint
Summary
Flame through 2.4.0 contains an improper restriction of excessive authentication attempts vulnerability in the POST /api/auth login endpoint that allows unauthenticated attackers to brute-force the admin password. Attackers can submit unlimited password guesses without rate limiting, attempt counters, lockouts, or delays to gain full administrator access and modify application configuration.
CWE
  • CWE-307 - Improper Restriction of Excessive Authentication Attempts
Impacted products
Vendor Product Version
pawelmalak flame Affected: 0 , ≤ 2.4.0 (custom)
Create a notification for this product.
Date Public
2026-08-17 00:00
Show details on NVD website

{
  "containers": {
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "flame",
          "vendor": "pawelmalak",
          "versions": [
            {
              "lessThanOrEqual": "2.4.0",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "finder",
          "value": "Whispergate Security Research"
        }
      ],
      "datePublic": "2026-08-17T00:00:00.000Z",
      "descriptions": [
        {
          "lang": "en",
          "value": "Flame through 2.4.0 contains an improper restriction of excessive authentication attempts vulnerability in the POST /api/auth login endpoint that allows unauthenticated attackers to brute-force the admin password. Attackers can submit unlimited password guesses without rate limiting, attempt counters, lockouts, or delays to gain full administrator access and modify application configuration."
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "attackComplexity": "HIGH",
            "attackRequirements": "PRESENT",
            "attackVector": "NETWORK",
            "baseScore": 8.3,
            "baseSeverity": "HIGH",
            "privilegesRequired": "NONE",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "vectorString": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N",
            "version": "4.0",
            "vulnAvailabilityImpact": "NONE",
            "vulnConfidentialityImpact": "LOW",
            "vulnIntegrityImpact": "HIGH"
          },
          "format": "CVSS"
        },
        {
          "cvssV3_1": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N",
            "version": "3.1"
          },
          "format": "CVSS"
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-307",
              "description": "Improper Restriction of Excessive Authentication Attempts",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-09-25T22:04:01.425Z",
        "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "shortName": "VulnCheck"
      },
      "references": [
        {
          "name": "GitHub Issue #494 (finding 1)",
          "tags": [
            "issue-tracking"
          ],
          "url": "https://github.com/pawelmalak/flame/issues/494"
        },
        {
          "name": "POST /api/auth registered with no rate limiting",
          "tags": [
            "technical-description"
          ],
          "url": "https://github.com/pawelmalak/flame/blob/v2.4.0/routes/auth.js#L7"
        },
        {
          "name": "login compares the single admin password and issues a JWT",
          "tags": [
            "technical-description"
          ],
          "url": "https://github.com/pawelmalak/flame/blob/v2.4.0/controllers/auth/login.js#L11-L22"
        },
        {
          "name": "Docker image default PASSWORD",
          "tags": [
            "technical-description"
          ],
          "url": "https://github.com/pawelmalak/flame/blob/v2.4.0/.docker/Dockerfile#L28"
        },
        {
          "tags": [
            "product"
          ],
          "url": "https://github.com/pawelmalak/flame"
        },
        {
          "name": "VulnCheck Advisory: Flame through 2.4.0 Brute-Force Attack via Login Endpoint",
          "tags": [
            "third-party-advisory"
          ],
          "url": "https://www.vulncheck.com/advisories/flame-through-2.4.0-brute-force-attack-via-login-endpoint"
        }
      ],
      "title": "Flame through 2.4.0 Brute-Force Attack via Login Endpoint",
      "x_generator": {
        "engine": "vulncheck-endgame"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
    "assignerShortName": "VulnCheck",
    "cveId": "CVE-2026-100501",
    "datePublished": "2026-09-25T22:04:01.425Z",
    "dateReserved": "2026-09-25T21:39:02.327Z",
    "dateUpdated": "2026-09-25T22:04:01.425Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-93650 (GCVE-0-2026-93650)

Vulnerability from cvelistv5 – Published: 2026-09-18 18:15 – Updated: 2026-09-18 19:47
VLAI
Title
Saleor throttling.py get_client_ip excessive authentication
Summary
A vulnerability was determined in Saleor up to 3.20.118/3.21.54/3.22.47/3.23.14. This vulnerability affects the function get_client_ip of the file saleor/account/throttling.py. Executing a manipulation can lead to improper restriction of excessive authentication attempts. The attack can be executed remotely. The attack requires a high level of complexity. It is stated that the exploitability is difficult. The exploit has been publicly disclosed and may be utilized. The projects own issue #19203 internal ticket admits "IP can be spoofed in most deployments" and that its REAL_IP_ENVIRON-type setting bypasses get_client_ip; fix (right-to-left RFC 7239 hop selection) proposed but still unmerged. The vendor explains within an email, that "[t]his is not a vulnerability, this is working at intended, Saleor expects XFF to be configured properly".
SSVC
Exploitation: poc Automatable: no Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-18 19:47 UTC
CWE
  • CWE-307 - Improper Restriction of Excessive Authentication Attempts
  • CWE-799 - Improper Control of Interaction Frequency
References
Impacted products
Vendor Product Version
n/a Saleor Affected: 3.20.118
Affected: 3.21.0
Affected: 3.21.1
Affected: 3.21.2
Affected: 3.21.3
Affected: 3.21.4
Affected: 3.21.5
Affected: 3.21.6
Affected: 3.21.7
Affected: 3.21.8
Affected: 3.21.9
Affected: 3.21.10
Affected: 3.21.11
Affected: 3.21.12
Affected: 3.21.13
Affected: 3.21.14
Affected: 3.21.15
Affected: 3.21.16
Affected: 3.21.17
Affected: 3.21.18
Affected: 3.21.19
Affected: 3.21.20
Affected: 3.21.21
Affected: 3.21.22
Affected: 3.21.23
Affected: 3.21.24
Affected: 3.21.25
Affected: 3.21.26
Affected: 3.21.27
Affected: 3.21.28
Affected: 3.21.29
Affected: 3.21.30
Affected: 3.21.31
Affected: 3.21.32
Affected: 3.21.33
Affected: 3.21.34
Affected: 3.21.35
Affected: 3.21.36
Affected: 3.21.37
Affected: 3.21.38
Affected: 3.21.39
Affected: 3.21.40
Affected: 3.21.41
Affected: 3.21.42
Affected: 3.21.43
Affected: 3.21.44
Affected: 3.21.45
Affected: 3.21.46
Affected: 3.21.47
Affected: 3.21.48
Affected: 3.21.49
Affected: 3.21.50
Affected: 3.21.51
Affected: 3.21.52
Affected: 3.21.53
Affected: 3.21.54
Affected: 3.22.0
Affected: 3.22.1
Affected: 3.22.2
Affected: 3.22.3
Affected: 3.22.4
Affected: 3.22.5
Affected: 3.22.6
Affected: 3.22.7
Affected: 3.22.8
Affected: 3.22.9
Affected: 3.22.10
Affected: 3.22.11
Affected: 3.22.12
Affected: 3.22.13
Affected: 3.22.14
Affected: 3.22.15
Affected: 3.22.16
Affected: 3.22.17
Affected: 3.22.18
Affected: 3.22.19
Affected: 3.22.20
Affected: 3.22.21
Affected: 3.22.22
Affected: 3.22.23
Affected: 3.22.24
Affected: 3.22.25
Affected: 3.22.26
Affected: 3.22.27
Affected: 3.22.28
Affected: 3.22.29
Affected: 3.22.30
Affected: 3.22.31
Affected: 3.22.32
Affected: 3.22.33
Affected: 3.22.34
Affected: 3.22.35
Affected: 3.22.36
Affected: 3.22.37
Affected: 3.22.38
Affected: 3.22.39
Affected: 3.22.40
Affected: 3.22.41
Affected: 3.22.42
Affected: 3.22.43
Affected: 3.22.44
Affected: 3.22.45
Affected: 3.22.46
Affected: 3.22.47
Affected: 3.23.0
Affected: 3.23.1
Affected: 3.23.2
Affected: 3.23.3
Affected: 3.23.4
Affected: 3.23.5
Affected: 3.23.6
Affected: 3.23.7
Affected: 3.23.8
Affected: 3.23.9
Affected: 3.23.10
Affected: 3.23.11
Affected: 3.23.12
Affected: 3.23.13
Affected: 3.23.14
    cpe:2.3:a:saleor:saleor:*:*:*:*:*:*:*:*
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-93650",
                "options": [
                  {
                    "Exploitation": "poc"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-09-18T19:47:42.986649Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-09-18T19:47:52.282Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "cpes": [
            "cpe:2.3:a:saleor:saleor:*:*:*:*:*:*:*:*"
          ],
          "product": "Saleor",
          "vendor": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "3.20.118"
            },
            {
              "status": "affected",
              "version": "3.21.0"
            },
            {
              "status": "affected",
              "version": "3.21.1"
            },
            {
              "status": "affected",
              "version": "3.21.2"
            },
            {
              "status": "affected",
              "version": "3.21.3"
            },
            {
              "status": "affected",
              "version": "3.21.4"
            },
            {
              "status": "affected",
              "version": "3.21.5"
            },
            {
              "status": "affected",
              "version": "3.21.6"
            },
            {
              "status": "affected",
              "version": "3.21.7"
            },
            {
              "status": "affected",
              "version": "3.21.8"
            },
            {
              "status": "affected",
              "version": "3.21.9"
            },
            {
              "status": "affected",
              "version": "3.21.10"
            },
            {
              "status": "affected",
              "version": "3.21.11"
            },
            {
              "status": "affected",
              "version": "3.21.12"
            },
            {
              "status": "affected",
              "version": "3.21.13"
            },
            {
              "status": "affected",
              "version": "3.21.14"
            },
            {
              "status": "affected",
              "version": "3.21.15"
            },
            {
              "status": "affected",
              "version": "3.21.16"
            },
            {
              "status": "affected",
              "version": "3.21.17"
            },
            {
              "status": "affected",
              "version": "3.21.18"
            },
            {
              "status": "affected",
              "version": "3.21.19"
            },
            {
              "status": "affected",
              "version": "3.21.20"
            },
            {
              "status": "affected",
              "version": "3.21.21"
            },
            {
              "status": "affected",
              "version": "3.21.22"
            },
            {
              "status": "affected",
              "version": "3.21.23"
            },
            {
              "status": "affected",
              "version": "3.21.24"
            },
            {
              "status": "affected",
              "version": "3.21.25"
            },
            {
              "status": "affected",
              "version": "3.21.26"
            },
            {
              "status": "affected",
              "version": "3.21.27"
            },
            {
              "status": "affected",
              "version": "3.21.28"
            },
            {
              "status": "affected",
              "version": "3.21.29"
            },
            {
              "status": "affected",
              "version": "3.21.30"
            },
            {
              "status": "affected",
              "version": "3.21.31"
            },
            {
              "status": "affected",
              "version": "3.21.32"
            },
            {
              "status": "affected",
              "version": "3.21.33"
            },
            {
              "status": "affected",
              "version": "3.21.34"
            },
            {
              "status": "affected",
              "version": "3.21.35"
            },
            {
              "status": "affected",
              "version": "3.21.36"
            },
            {
              "status": "affected",
              "version": "3.21.37"
            },
            {
              "status": "affected",
              "version": "3.21.38"
            },
            {
              "status": "affected",
              "version": "3.21.39"
            },
            {
              "status": "affected",
              "version": "3.21.40"
            },
            {
              "status": "affected",
              "version": "3.21.41"
            },
            {
              "status": "affected",
              "version": "3.21.42"
            },
            {
              "status": "affected",
              "version": "3.21.43"
            },
            {
              "status": "affected",
              "version": "3.21.44"
            },
            {
              "status": "affected",
              "version": "3.21.45"
            },
            {
              "status": "affected",
              "version": "3.21.46"
            },
            {
              "status": "affected",
              "version": "3.21.47"
            },
            {
              "status": "affected",
              "version": "3.21.48"
            },
            {
              "status": "affected",
              "version": "3.21.49"
            },
            {
              "status": "affected",
              "version": "3.21.50"
            },
            {
              "status": "affected",
              "version": "3.21.51"
            },
            {
              "status": "affected",
              "version": "3.21.52"
            },
            {
              "status": "affected",
              "version": "3.21.53"
            },
            {
              "status": "affected",
              "version": "3.21.54"
            },
            {
              "status": "affected",
              "version": "3.22.0"
            },
            {
              "status": "affected",
              "version": "3.22.1"
            },
            {
              "status": "affected",
              "version": "3.22.2"
            },
            {
              "status": "affected",
              "version": "3.22.3"
            },
            {
              "status": "affected",
              "version": "3.22.4"
            },
            {
              "status": "affected",
              "version": "3.22.5"
            },
            {
              "status": "affected",
              "version": "3.22.6"
            },
            {
              "status": "affected",
              "version": "3.22.7"
            },
            {
              "status": "affected",
              "version": "3.22.8"
            },
            {
              "status": "affected",
              "version": "3.22.9"
            },
            {
              "status": "affected",
              "version": "3.22.10"
            },
            {
              "status": "affected",
              "version": "3.22.11"
            },
            {
              "status": "affected",
              "version": "3.22.12"
            },
            {
              "status": "affected",
              "version": "3.22.13"
            },
            {
              "status": "affected",
              "version": "3.22.14"
            },
            {
              "status": "affected",
              "version": "3.22.15"
            },
            {
              "status": "affected",
              "version": "3.22.16"
            },
            {
              "status": "affected",
              "version": "3.22.17"
            },
            {
              "status": "affected",
              "version": "3.22.18"
            },
            {
              "status": "affected",
              "version": "3.22.19"
            },
            {
              "status": "affected",
              "version": "3.22.20"
            },
            {
              "status": "affected",
              "version": "3.22.21"
            },
            {
              "status": "affected",
              "version": "3.22.22"
            },
            {
              "status": "affected",
              "version": "3.22.23"
            },
            {
              "status": "affected",
              "version": "3.22.24"
            },
            {
              "status": "affected",
              "version": "3.22.25"
            },
            {
              "status": "affected",
              "version": "3.22.26"
            },
            {
              "status": "affected",
              "version": "3.22.27"
            },
            {
              "status": "affected",
              "version": "3.22.28"
            },
            {
              "status": "affected",
              "version": "3.22.29"
            },
            {
              "status": "affected",
              "version": "3.22.30"
            },
            {
              "status": "affected",
              "version": "3.22.31"
            },
            {
              "status": "affected",
              "version": "3.22.32"
            },
            {
              "status": "affected",
              "version": "3.22.33"
            },
            {
              "status": "affected",
              "version": "3.22.34"
            },
            {
              "status": "affected",
              "version": "3.22.35"
            },
            {
              "status": "affected",
              "version": "3.22.36"
            },
            {
              "status": "affected",
              "version": "3.22.37"
            },
            {
              "status": "affected",
              "version": "3.22.38"
            },
            {
              "status": "affected",
              "version": "3.22.39"
            },
            {
              "status": "affected",
              "version": "3.22.40"
            },
            {
              "status": "affected",
              "version": "3.22.41"
            },
            {
              "status": "affected",
              "version": "3.22.42"
            },
            {
              "status": "affected",
              "version": "3.22.43"
            },
            {
              "status": "affected",
              "version": "3.22.44"
            },
            {
              "status": "affected",
              "version": "3.22.45"
            },
            {
              "status": "affected",
              "version": "3.22.46"
            },
            {
              "status": "affected",
              "version": "3.22.47"
            },
            {
              "status": "affected",
              "version": "3.23.0"
            },
            {
              "status": "affected",
              "version": "3.23.1"
            },
            {
              "status": "affected",
              "version": "3.23.2"
            },
            {
              "status": "affected",
              "version": "3.23.3"
            },
            {
              "status": "affected",
              "version": "3.23.4"
            },
            {
              "status": "affected",
              "version": "3.23.5"
            },
            {
              "status": "affected",
              "version": "3.23.6"
            },
            {
              "status": "affected",
              "version": "3.23.7"
            },
            {
              "status": "affected",
              "version": "3.23.8"
            },
            {
              "status": "affected",
              "version": "3.23.9"
            },
            {
              "status": "affected",
              "version": "3.23.10"
            },
            {
              "status": "affected",
              "version": "3.23.11"
            },
            {
              "status": "affected",
              "version": "3.23.12"
            },
            {
              "status": "affected",
              "version": "3.23.13"
            },
            {
              "status": "affected",
              "version": "3.23.14"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "reporter",
          "value": "ZAST.AI (VulDB User)"
        },
        {
          "lang": "en",
          "type": "coordinator",
          "value": "VulDB CNA Team"
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "A vulnerability was determined in Saleor up to 3.20.118/3.21.54/3.22.47/3.23.14. This vulnerability affects the function get_client_ip of the file saleor/account/throttling.py. Executing a manipulation can lead to improper restriction of excessive authentication attempts. The attack can be executed remotely. The attack requires a high level of complexity. It is stated that the exploitability is difficult. The exploit has been publicly disclosed and may be utilized. The projects own issue #19203 internal ticket admits \"IP can be spoofed in most deployments\" and that its REAL_IP_ENVIRON-type setting bypasses get_client_ip; fix (right-to-left RFC 7239 hop selection) proposed but still unmerged. The vendor explains within an email, that \"[t]his is not a vulnerability, this is working at intended, Saleor expects XFF to be configured properly\"."
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "baseScore": 6.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P",
            "version": "4.0"
          }
        },
        {
          "cvssV3_1": {
            "baseScore": 3.7,
            "baseSeverity": "LOW",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R",
            "version": "3.1"
          }
        },
        {
          "cvssV3_0": {
            "baseScore": 3.7,
            "baseSeverity": "LOW",
            "vectorString": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R",
            "version": "3.0"
          }
        },
        {
          "cvssV2_0": {
            "baseScore": 2.6,
            "vectorString": "AV:N/AC:H/Au:N/C:P/I:N/A:N/E:POC/RL:ND/RC:C",
            "version": "2.0"
          }
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-307",
              "description": "Improper Restriction of Excessive Authentication Attempts",
              "lang": "en",
              "type": "CWE"
            }
          ]
        },
        {
          "descriptions": [
            {
              "cweId": "CWE-799",
              "description": "Improper Control of Interaction Frequency",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-09-18T18:15:10.080Z",
        "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "shortName": "VulDB"
      },
      "references": [
        {
          "name": "VDB-407477 | Saleor throttling.py get_client_ip excessive authentication",
          "tags": [
            "vdb-entry",
            "technical-description"
          ],
          "url": "https://vuldb.com/vuln/407477"
        },
        {
          "name": "VDB-407477 | CTI Indicators (IOB, IOC, TTP, IOA)",
          "tags": [
            "signature",
            "permissions-required"
          ],
          "url": "https://vuldb.com/vuln/407477/cti"
        },
        {
          "name": "CVE-2026-93650 | CVE Analysis and Report",
          "tags": [
            "third-party-advisory"
          ],
          "url": "https://vuldb.com/cve/CVE-2026-93650"
        },
        {
          "name": "Submit #933655 | saleor \u003c=3.23.14 Improper Restriction of Excessive Authentication Attempts",
          "tags": [
            "third-party-advisory"
          ],
          "url": "https://vuldb.com/submit/933655"
        },
        {
          "tags": [
            "exploit"
          ],
          "url": "https://github.com/zast-ai/vulnerability-reports/blob/main/saleor/bruteforce.md"
        },
        {
          "tags": [
            "issue-tracking"
          ],
          "url": "https://github.com/saleor/saleor/issues/19203"
        },
        {
          "tags": [
            "product"
          ],
          "url": "https://github.com/saleor/saleor/"
        }
      ],
      "timeline": [
        {
          "lang": "en",
          "time": "2026-09-18T00:00:00.000Z",
          "value": "Advisory disclosed"
        },
        {
          "lang": "en",
          "time": "2026-09-18T02:00:00.000Z",
          "value": "VulDB entry created"
        },
        {
          "lang": "en",
          "time": "2026-09-18T15:13:21.000Z",
          "value": "VulDB entry last update"
        }
      ],
      "title": "Saleor throttling.py get_client_ip excessive authentication",
      "x_generator": [
        "VulDB PVTS v202609"
      ]
    }
  },
  "cveMetadata": {
    "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
    "assignerShortName": "VulDB",
    "cveId": "CVE-2026-93650",
    "datePublished": "2026-09-18T18:15:10.080Z",
    "dateReserved": "2026-09-18T13:07:36.010Z",
    "dateUpdated": "2026-09-18T19:47:52.282Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-92583 (GCVE-0-2026-92583)

Vulnerability from cvelistv5 – Published: 2026-09-16 21:46 – Updated: 2026-09-17 14:49
VLAI
Title
AVideo through 29.0 Rate Limit Bypass via Non-Atomic Counter Increment
Summary
AVideo through 29.0 contains a race condition in the enforceRateLimit() function that fails to atomically increment rate limit counters, allowing attackers to bypass all rate limits including login brute-force protection by issuing concurrent requests. Attackers can submit parallel credential attempts to exceed the documented 30-attempts-per-5-minutes login limit by an arbitrary factor determined only by their connection concurrency.
SSVC
Exploitation: poc Automatable: yes Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-17 14:47 UTC
CWE
  • CWE-307 - Improper Restriction of Excessive Authentication Attempts
References
Impacted products
Vendor Product Version
WWBN AVideo Affected: 0 , ≤ 29.0 (custom)
    cpe:2.3:a:wwbn:avideo:*:*:*:*:*:*:*:*
Create a notification for this product.
Date Public
2026-09-01 00:00
Credits
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-92583",
                "options": [
                  {
                    "Exploitation": "poc"
                  },
                  {
                    "Automatable": "yes"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-09-17T14:47:33.195595Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-09-17T14:49:33.344Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "references": [
          {
            "tags": [
              "exploit"
            ],
            "url": "https://github.com/WWBN/AVideo/security/advisories/GHSA-8jrm-qg5f-966w"
          }
        ],
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "AVideo",
          "vendor": "WWBN",
          "versions": [
            {
              "lessThanOrEqual": "29.0",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:a:wwbn:avideo:*:*:*:*:*:*:*:*",
                  "versionEndIncluding": "29.0",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "reporter",
          "value": "rajivraj"
        }
      ],
      "datePublic": "2026-09-01T00:00:00.000Z",
      "descriptions": [
        {
          "lang": "en",
          "value": "AVideo through 29.0 contains a race condition in the enforceRateLimit() function that fails to atomically increment rate limit counters, allowing attackers to bypass all rate limits including login brute-force protection by issuing concurrent requests. Attackers can submit parallel credential attempts to exceed the documented 30-attempts-per-5-minutes login limit by an arbitrary factor determined only by their connection concurrency."
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "baseScore": 6.9,
            "baseSeverity": "MEDIUM",
            "privilegesRequired": "NONE",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N",
            "version": "4.0",
            "vulnAvailabilityImpact": "NONE",
            "vulnConfidentialityImpact": "LOW",
            "vulnIntegrityImpact": "LOW"
          },
          "format": "CVSS"
        },
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
            "version": "3.1"
          },
          "format": "CVSS"
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-307",
              "description": "Improper Restriction of Excessive Authentication Attempts",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-09-16T21:46:50.833Z",
        "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "shortName": "VulnCheck"
      },
      "references": [
        {
          "name": "GitHub Security Advisory (GHSA-8jrm-qg5f-966w)",
          "tags": [
            "vendor-advisory"
          ],
          "url": "https://github.com/WWBN/AVideo/security/advisories/GHSA-8jrm-qg5f-966w"
        },
        {
          "name": "VulnCheck Advisory: AVideo through 29.0 Rate Limit Bypass via Non-Atomic Counter Increment",
          "tags": [
            "third-party-advisory"
          ],
          "url": "https://www.vulncheck.com/advisories/avideo-through-29.0-rate-limit-bypass-via-non-atomic-counter-increment"
        }
      ],
      "title": "AVideo through 29.0 Rate Limit Bypass via Non-Atomic Counter Increment",
      "x_generator": {
        "engine": "vulncheck-endgame"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
    "assignerShortName": "VulnCheck",
    "cveId": "CVE-2026-92583",
    "datePublished": "2026-09-16T21:46:50.833Z",
    "dateReserved": "2026-09-16T13:47:20.117Z",
    "dateUpdated": "2026-09-17T14:49:33.344Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-92082 (GCVE-0-2026-92082)

Vulnerability from cvelistv5 – Published: 2026-09-15 14:04 – Updated: 2026-09-15 14:58 X_Open Source
VLAI
Title
Payara Server is vulnerable to brute-force login attacks due to the absence of a limit on failed login attempts
Summary
By default, Payara Server does not limit the number of failed login attempts, which can leave it vulnerable to brute force login attacks. To mitigate this, Payara Server includes built-in automatic attack protection. For configuration details, see  https://docs.azul.com/payara/technical-documentation/payara-server-documentation/security-guide/administering-system-security.html .
SSVC
Exploitation: none Automatable: no Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-15 14:58 UTC
CWE
  • CWE-307 - Improper restriction of excessive authentication attempts
Impacted products
Vendor Product Version
Payara Payara Server Affected: 7.0.0 , < 7.2.0 (semver)
Affected: 7.2025.1 , < 7.2026.7 (custom)
Affected: 6.0.0 , < 6.40.0 (semver)
Affected: 5.20.0 , < 5.89.0 (semver)
Affected: 4.1.144 , < 4.1.2.191.57 (custom)
Affected: 6.2023.1 (custom)
Affected: 5.2020.1 (custom)
Create a notification for this product.
Date Public
2026-09-15 13:09
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-92082",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-09-15T14:58:27.927898Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-09-15T14:58:50.917Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "affected",
          "modules": [
            "Admin GUI"
          ],
          "packageName": "org.glassfish.admingui.common.security",
          "product": "Payara Server",
          "programFiles": [
            "org.glassfish.admingui.common.security.AdminConsoleAuthModule"
          ],
          "repo": "https://github.com/payara/Payara/",
          "vendor": "Payara",
          "versions": [
            {
              "lessThan": "7.2.0",
              "status": "affected",
              "version": "7.0.0",
              "versionType": "semver"
            },
            {
              "lessThan": "7.2026.7",
              "status": "affected",
              "version": "7.2025.1",
              "versionType": "custom"
            },
            {
              "lessThan": "6.40.0",
              "status": "affected",
              "version": "6.0.0",
              "versionType": "semver"
            },
            {
              "lessThan": "5.89.0",
              "status": "affected",
              "version": "5.20.0",
              "versionType": "semver"
            },
            {
              "lessThan": "4.1.2.191.57",
              "status": "affected",
              "version": "4.1.144",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "6.2023.1",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "5.2020.1",
              "versionType": "custom"
            }
          ]
        }
      ],
      "datePublic": "2026-09-15T13:09:00.000Z",
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "By default, Payara Server does not limit the number of failed login attempts, which can leave it vulnerable to brute force login attacks. To mitigate this, Payara Server includes built-in automatic attack protection. For configuration details, see\u0026nbsp;\u003ca href=\"https://docs.azul.com/payara/technical-documentation/payara-server-documentation/security-guide/administering-system-security.html\" target=\"_blank\"\u003ehttps://docs.azul.com/payara/technical-documentation/payara-server-documentation/security-guide/administering-system-security.html\u003c/a\u003e."
            }
          ],
          "value": "By default, Payara Server does not limit the number of failed login attempts, which can leave it vulnerable to brute force login attacks. To mitigate this, Payara Server includes built-in automatic attack protection. For configuration details, see\u00a0 https://docs.azul.com/payara/technical-documentation/payara-server-documentation/security-guide/administering-system-security.html ."
        }
      ],
      "impacts": [
        {
          "capecId": "CAPEC-49",
          "descriptions": [
            {
              "lang": "en",
              "value": "CAPEC-49 Password Brute Forcing"
            }
          ]
        },
        {
          "capecId": "CAPEC-16",
          "descriptions": [
            {
              "lang": "en",
              "value": "CAPEC-16 Dictionary-based Password Attack"
            }
          ]
        },
        {
          "capecId": "CAPEC-565",
          "descriptions": [
            {
              "lang": "en",
              "value": "CAPEC-565 Password Spraying"
            }
          ]
        },
        {
          "capecId": "CAPEC-600",
          "descriptions": [
            {
              "lang": "en",
              "value": "CAPEC-600 Credential Stuffing"
            }
          ]
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "Automatable": "YES",
            "Recovery": "USER",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "ADJACENT",
            "baseScore": 6.3,
            "baseSeverity": "MEDIUM",
            "exploitMaturity": "NOT_DEFINED",
            "privilegesRequired": "NONE",
            "providerUrgency": "AMBER",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "HIGH",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "CONCENTRATED",
            "vectorString": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N/AU:Y/R:U/V:C/RE:L/U:Amber",
            "version": "4.0",
            "vulnAvailabilityImpact": "NONE",
            "vulnConfidentialityImpact": "LOW",
            "vulnIntegrityImpact": "NONE",
            "vulnerabilityResponseEffort": "LOW"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-307",
              "description": "CWE-307 Improper restriction of excessive authentication attempts",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-09-15T14:04:25.241Z",
        "orgId": "769c9ae7-73c3-4e47-ae19-903170fc3eb8",
        "shortName": "Payara"
      },
      "references": [
        {
          "tags": [
            "release-notes"
          ],
          "url": "https://docs.azul.com/payara/release-notes/release-notes-7.2.0.html"
        },
        {
          "tags": [
            "release-notes"
          ],
          "url": "https://docs.azul.com/payara/version/6/release-notes/release-notes-6.40.0.html"
        },
        {
          "tags": [
            "release-notes"
          ],
          "url": "https://docs.azul.com/payara/version/5/release-notes/release-notes-5.89.0.html"
        },
        {
          "tags": [
            "release-notes"
          ],
          "url": "https://docs.azul.com/payara/version/4/release-notes/release-notes-4.1.2.191.57.html"
        },
        {
          "tags": [
            "release-notes"
          ],
          "url": "https://docs.azul.com/payara-community/release-notes/release-notes-7.2026.7.html"
        }
      ],
      "source": {
        "advisory": "CVE-2024-9342",
        "discovery": "UPSTREAM"
      },
      "tags": [
        "x_open-source"
      ],
      "title": "Payara Server is vulnerable to brute-force login attacks due to the absence of a limit on failed login attempts",
      "x_generator": {
        "engine": "Vulnogram 1.0.5"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "769c9ae7-73c3-4e47-ae19-903170fc3eb8",
    "assignerShortName": "Payara",
    "cveId": "CVE-2026-92082",
    "datePublished": "2026-09-15T14:04:25.241Z",
    "dateReserved": "2026-09-15T13:03:29.440Z",
    "dateUpdated": "2026-09-15T14:58:50.917Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-91973 (GCVE-0-2026-91973)

Vulnerability from cvelistv5 – Published: 2026-09-15 15:18 – Updated: 2026-09-15 15:55
VLAI
Title
Vikunja before 2.6.0 Authentication Bypass via CalDAV BasicAuth
Summary
Vikunja before 2.6.0 contains an authentication bypass vulnerability in CalDAV BasicAuth endpoints that lack rate limiting protection. Remote unauthenticated attackers can issue unbounded credential-guessing requests against /dav, /.well-known, and /feeds routes to bypass the instance's anti-brute-force controls and compromise password-only accounts.
SSVC
Exploitation: poc Automatable: yes Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-15 15:53 UTC
CWE
  • CWE-307 - Improper Restriction of Excessive Authentication Attempts
References
Impacted products
Vendor Product Version
go-vikunja vikunja Affected: 0 , < 2.6.0 (semver)
Unaffected: 2.6.0 (semver)
    cpe:2.3:a:vikunja:vikunja:*:*:*:*:*:*:*:*
Create a notification for this product.
Date Public
2026-08-31 00:00
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-91973",
                "options": [
                  {
                    "Exploitation": "poc"
                  },
                  {
                    "Automatable": "yes"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-09-15T15:53:33.159049Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-09-15T15:55:04.161Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "references": [
          {
            "tags": [
              "exploit"
            ],
            "url": "https://github.com/go-vikunja/vikunja/security/advisories/GHSA-m469-88xx-8rx2"
          }
        ],
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "vikunja",
          "vendor": "go-vikunja",
          "versions": [
            {
              "lessThan": "2.6.0",
              "status": "affected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "2.6.0",
              "versionType": "semver"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:a:vikunja:vikunja:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "2.6.0",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "reporter",
          "value": "JellowBeanz26"
        }
      ],
      "datePublic": "2026-08-31T00:00:00.000Z",
      "descriptions": [
        {
          "lang": "en",
          "value": "Vikunja before 2.6.0 contains an authentication bypass vulnerability in CalDAV BasicAuth endpoints that lack rate limiting protection. Remote unauthenticated attackers can issue unbounded credential-guessing requests against /dav, /.well-known, and /feeds routes to bypass the instance\u0027s anti-brute-force controls and compromise password-only accounts."
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "baseScore": 8.7,
            "baseSeverity": "HIGH",
            "exploitMaturity": "NOT_DEFINED",
            "privilegesRequired": "NONE",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
            "version": "4.0",
            "vulnAvailabilityImpact": "NONE",
            "vulnConfidentialityImpact": "HIGH",
            "vulnIntegrityImpact": "NONE",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "format": "CVSS"
        },
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "format": "CVSS"
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-307",
              "description": "Improper Restriction of Excessive Authentication Attempts",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-09-15T15:18:23.488Z",
        "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "shortName": "VulnCheck"
      },
      "references": [
        {
          "name": "GitHub Security Advisory (GHSA-m469-88xx-8rx2)",
          "tags": [
            "vendor-advisory"
          ],
          "url": "https://github.com/go-vikunja/vikunja/security/advisories/GHSA-m469-88xx-8rx2"
        },
        {
          "name": "VulnCheck Advisory: Vikunja before 2.6.0 Authentication Bypass via CalDAV BasicAuth",
          "tags": [
            "third-party-advisory"
          ],
          "url": "https://www.vulncheck.com/advisories/vikunja-before-2.6.0-authentication-bypass-via-caldav-basicauth"
        }
      ],
      "title": "Vikunja before 2.6.0 Authentication Bypass via CalDAV BasicAuth",
      "x_generator": {
        "engine": "vulncheck-endgame"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
    "assignerShortName": "VulnCheck",
    "cveId": "CVE-2026-91973",
    "datePublished": "2026-09-15T15:18:23.488Z",
    "dateReserved": "2026-09-15T11:09:54.873Z",
    "dateUpdated": "2026-09-15T15:55:04.161Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-91972 (GCVE-0-2026-91972)

Vulnerability from cvelistv5 – Published: 2026-09-15 15:18 – Updated: 2026-09-17 15:12
VLAI
Title
Vikunja before 2.6.0 Authentication Bypass via Unthrottled API
Summary
Vikunja versions before 2.6.0 fail to apply rate limiting to /api/v2 public authentication endpoints including login, register, password-reset, and OAuth token routes. Remote unauthenticated attackers can perform unbounded credential guessing, account enumeration, and password-reset flooding attacks without throttling restrictions.
SSVC
Exploitation: poc Automatable: yes Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-17 15:11 UTC
CWE
  • CWE-307 - Improper Restriction of Excessive Authentication Attempts
References
Impacted products
Vendor Product Version
go-vikunja vikunja Affected: 0 , < 2.6.0 (semver)
Unaffected: 2.6.0 (semver)
    cpe:2.3:a:vikunja:vikunja:*:*:*:*:*:*:*:*
Create a notification for this product.
Date Public
2026-08-31 00:00
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-91972",
                "options": [
                  {
                    "Exploitation": "poc"
                  },
                  {
                    "Automatable": "yes"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-09-17T15:11:53.582933Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-09-17T15:12:40.377Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "references": [
          {
            "tags": [
              "exploit"
            ],
            "url": "https://github.com/go-vikunja/vikunja/security/advisories/GHSA-6rvj-qwjf-3m4q"
          }
        ],
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "vikunja",
          "vendor": "go-vikunja",
          "versions": [
            {
              "lessThan": "2.6.0",
              "status": "affected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "2.6.0",
              "versionType": "semver"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:a:vikunja:vikunja:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "2.6.0",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "reporter",
          "value": "JellowBeanz26"
        }
      ],
      "datePublic": "2026-08-31T00:00:00.000Z",
      "descriptions": [
        {
          "lang": "en",
          "value": "Vikunja versions before 2.6.0 fail to apply rate limiting to /api/v2 public authentication endpoints including login, register, password-reset, and OAuth token routes. Remote unauthenticated attackers can perform unbounded credential guessing, account enumeration, and password-reset flooding attacks without throttling restrictions."
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "baseScore": 8.7,
            "baseSeverity": "HIGH",
            "exploitMaturity": "NOT_DEFINED",
            "privilegesRequired": "NONE",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
            "version": "4.0",
            "vulnAvailabilityImpact": "NONE",
            "vulnConfidentialityImpact": "HIGH",
            "vulnIntegrityImpact": "NONE",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "format": "CVSS"
        },
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "format": "CVSS"
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-307",
              "description": "Improper Restriction of Excessive Authentication Attempts",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-09-15T15:18:22.792Z",
        "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "shortName": "VulnCheck"
      },
      "references": [
        {
          "name": "GitHub Security Advisory (GHSA-6rvj-qwjf-3m4q)",
          "tags": [
            "vendor-advisory"
          ],
          "url": "https://github.com/go-vikunja/vikunja/security/advisories/GHSA-6rvj-qwjf-3m4q"
        },
        {
          "name": "VulnCheck Advisory: Vikunja before 2.6.0 Authentication Bypass via Unthrottled API",
          "tags": [
            "third-party-advisory"
          ],
          "url": "https://www.vulncheck.com/advisories/vikunja-before-2.6.0-authentication-bypass-via-unthrottled-api"
        }
      ],
      "title": "Vikunja before 2.6.0 Authentication Bypass via Unthrottled API",
      "x_generator": {
        "engine": "vulncheck-endgame"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
    "assignerShortName": "VulnCheck",
    "cveId": "CVE-2026-91972",
    "datePublished": "2026-09-15T15:18:22.792Z",
    "dateReserved": "2026-09-15T11:09:54.873Z",
    "dateUpdated": "2026-09-17T15:12:40.377Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-89174 (GCVE-0-2026-89174)

Vulnerability from cvelistv5 – Published: 2026-09-11 07:31 – Updated: 2026-09-11 15:49
VLAI
Title
Kingdom Communication Associated|Smart Video Intercom System - Missing Burte-force Protection
Summary
Smart Video Intercom System developed by Kingdom Communication Associated has a Missing Brute-force Protection vulnerability. Unauthenticated remote attackers can gain access to valid accounts through a large number of login attempts.
SSVC
Exploitation: none Automatable: yes Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-11 15:47 UTC
CWE
  • CWE-307 - Improper Restriction of Excessive Authentication Attempts
References
Date Public
2026-09-11 07:28
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-89174",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "yes"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-09-11T15:47:22.171888Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-09-11T15:49:30.661Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "EH3040",
          "vendor": "Kingdom Communication Associated",
          "versions": [
            {
              "lessThan": "2.5.0A",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "EH4200",
          "vendor": "Kingdom Communication Associated",
          "versions": [
            {
              "lessThan": "2.5.0A",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "EH1000B",
          "vendor": "Kingdom Communication Associated",
          "versions": [
            {
              "lessThan": "2.7.0A",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "EH2070",
          "vendor": "Kingdom Communication Associated",
          "versions": [
            {
              "lessThan": "2.8.0A",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        }
      ],
      "datePublic": "2026-09-11T07:28:00.000Z",
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eSmart Video Intercom System developed by Kingdom Communication Associated has a Missing Brute-force Protection vulnerability. Unauthenticated remote attackers can gain access to valid accounts through a large number of login attempts.\u003c/p\u003e"
            }
          ],
          "value": "Smart Video Intercom System developed by Kingdom Communication Associated has a Missing Brute-force Protection vulnerability. Unauthenticated remote attackers can gain access to valid accounts through a large number of login attempts."
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "baseScore": 8.7,
            "baseSeverity": "HIGH",
            "exploitMaturity": "NOT_DEFINED",
            "privilegesRequired": "NONE",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
            "version": "4.0",
            "vulnAvailabilityImpact": "NONE",
            "vulnConfidentialityImpact": "HIGH",
            "vulnIntegrityImpact": "NONE",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        },
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-307",
              "description": "CWE-307 Improper Restriction of Excessive Authentication Attempts",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-09-11T07:31:15.921Z",
        "orgId": "cded6c7f-6ce5-4948-8f87-aa7a3bbb6b0e",
        "shortName": "twcert"
      },
      "references": [
        {
          "tags": [
            "third-party-advisory"
          ],
          "url": "https://www.twcert.org.tw/tw/cp-132-11198-b8bba-1.html"
        },
        {
          "tags": [
            "third-party-advisory"
          ],
          "url": "https://www.twcert.org.tw/en/cp-139-11199-38e1e-2.html"
        }
      ],
      "solutions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eUpdate EH3040 to version 2.5.0A\u003cbr\u003eUpdate EH4200 to version 2.5.0A\u003cbr\u003eUpdate EH1000B to version 2.7.0A\u003cbr\u003eUpdate EH2070 to version 2.8.0A\u003c/p\u003e"
            }
          ],
          "value": "Update EH3040 to version 2.5.0A\nUpdate EH4200 to version 2.5.0A\nUpdate EH1000B to version 2.7.0A\nUpdate EH2070 to version 2.8.0A"
        }
      ],
      "source": {
        "advisory": "TVN-202609004",
        "discovery": "EXTERNAL"
      },
      "title": "Kingdom Communication Associated\uff5cSmart Video Intercom System - Missing Burte-force Protection",
      "x_generator": {
        "engine": "Vulnogram 1.0.5"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "cded6c7f-6ce5-4948-8f87-aa7a3bbb6b0e",
    "assignerShortName": "twcert",
    "cveId": "CVE-2026-89174",
    "datePublished": "2026-09-11T07:31:15.921Z",
    "dateReserved": "2026-09-11T06:14:46.734Z",
    "dateUpdated": "2026-09-11T15:49:30.661Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

Mitigation
Architecture and Design
  • Common protection mechanisms include:
  • Disconnecting the user after a small number of failed attempts
  • Implementing a timeout
  • Locking out a targeted account
  • Requiring a computational task on the user's part.
Mitigation MIT-4
Architecture and Design

Strategy: Libraries or Frameworks

  • Use a vetted library or framework that does not allow this weakness to occur or provides constructs that make this weakness easier to avoid [REF-1482].
  • Consider using libraries with authentication capabilities such as OpenSSL or the ESAPI Authenticator. [REF-45]
CAPEC-16: Dictionary-based Password Attack

An attacker tries each of the words in a dictionary as passwords to gain access to the system via some user's account. If the password chosen by the user was a word within the dictionary, this attack will be successful (in the absence of other mitigations). This is a specific instance of the password brute forcing attack pattern.

Dictionary Attacks differ from similar attacks such as Password Spraying (CAPEC-565) and Credential Stuffing (CAPEC-600), since they leverage unknown username/password combinations and don't care about inducing account lockouts.

CAPEC-49: Password Brute Forcing

An adversary tries every possible value for a password until they succeed. A brute force attack, if feasible computationally, will always be successful because it will essentially go through all possible passwords given the alphabet used (lower case letters, upper case letters, numbers, symbols, etc.) and the maximum length of the password.

CAPEC-560: Use of Known Domain Credentials

An adversary guesses or obtains (i.e. steals or purchases) legitimate credentials (e.g. userID/password) to achieve authentication and to perform authorized actions under the guise of an authenticated user or service.

CAPEC-565: Password Spraying

In a Password Spraying attack, an adversary tries a small list (e.g. 3-5) of common or expected passwords, often matching the target's complexity policy, against a known list of user accounts to gain valid credentials. The adversary tries a particular password for each user account, before moving onto the next password in the list. This approach assists the adversary in remaining undetected by avoiding rapid or frequent account lockouts. The adversary may then reattempt the process with additional passwords, once enough time has passed to prevent inducing a lockout.

CAPEC-600: Credential Stuffing

An adversary tries known username/password combinations against different systems, applications, or services to gain additional authenticated access. Credential Stuffing attacks rely upon the fact that many users leverage the same username/password combination for multiple systems, applications, and services.

CAPEC-652: Use of Known Kerberos Credentials

An adversary obtains (i.e. steals or purchases) legitimate Kerberos credentials (e.g. Kerberos service account userID/password or Kerberos Tickets) with the goal of achieving authenticated access to additional systems, applications, or services within the domain.

CAPEC-653: Use of Known Operating System Credentials

An adversary guesses or obtains (i.e. steals or purchases) legitimate operating system credentials (e.g. userID/password) to achieve authentication and to perform authorized actions on the system, under the guise of an authenticated user or service. This applies to any Operating System.