CRITICAL
9.1 CVE-2026-84479 Published 1 Sept 2026
AVideo Login Bypass via User-Agent Spoofing
Worried this affects one of your servers?
AVideo (current e01e41ecc and earlier) has a login-time security bypass vulnerability.
Three security controls (two-factor authentication, brute-force captcha escalation, and login/device audit history) rely solely on the client-supplied User-Agent header.
An attacker can bypass these controls by setting the User-Agent header to 'AVideoEncoder'.
- No patch is available at the time of publication.
Reference: CVE-2026-84479 on NVD
← Back to Security News