CRITICAL 9.1 CVE-2026-84479 Published 1 Sept 2026

AVideo Login Bypass via User-Agent Spoofing

Worried this affects one of your servers?

AVideo (current e01e41ecc and earlier) has a login-time security bypass vulnerability.

Three security controls (two-factor authentication, brute-force captcha escalation, and login/device audit history) rely solely on the client-supplied User-Agent header.

An attacker can bypass these controls by setting the User-Agent header to 'AVideoEncoder'.

  • No patch is available at the time of publication.

Reference: CVE-2026-84479 on NVD

← Back to Security News