Junglewise Threat Intelligence

CVE-2026-84479: WWBN AVideo authentication bypass via User-Agent header

CVE-2026-84479 · Severity: critical · CVSS 9.1 · Published 2026-09-01

Technologies: WWBN AVideo. Vendors: WWBN.

Executive brief

WWBN AVideo is a video hosting and streaming platform used by organizations to manage and distribute video content. A critical authentication flaw allows attackers with valid user credentials to bypass two-factor authentication, skip brute-force protection, and hide their login activity by simply changing the HTTP User-Agent header to a hardcoded value. This enables unauthorized account access even when strong authentication controls are enabled, compromising account security and compliance audit trails.

Technical details

The vulnerability is an authentication bypass resulting from trust of client-supplied HTTP headers. Three login-time security controls in WWBN AVideo (checkLoginAttempts/captcha escalation, two-factor authentication in the LoginControl plugin, and login audit logging) all depend on isAVideoEncoder() and isAVideoMobileApp() functions that match HTTP_USER_AGENT against hardcoded literals ("AVideoEncoder"/"AVideoMobileApp") with no cryptographic validation, IP checks, or shared secrets. An attacker with valid credentials can send User-Agent: AVideoEncoder to completely bypass all three controls in a single request. Additionally, a fourth defect causes 2FA to fail open when email delivery is unavailable—if the 2FA email cannot be sent, the session is left authenticated rather than rejected. The only remaining mitigation is IP-based rate limiting (30 requests per 5 minutes), which does not protect against a single credential-based login request.

Affected products

  • WWBN AVideo current (e01e41ecc) and earlier, including versions up to 29.0

Timeline

  • 2026-09-01: disclosed: Vulnerability disclosed; no patch available at time of publication
  • 2026-08-18: advisory: GitHub Security Advisory GHSA-m9m3-gwh2-337c published

References

Related threats