SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-86186

MEDIUM · CVSS 6.5 EPSS 0.18% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-05 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

AVideo API is vulnerable due to inadequate enforcement of rate limits when clients use a bot User-Agent header, enabling attackers to bypass protections for critical operations, including login attempts. This flaw allows for unlimited password guessing attempts from a single IP address, significantly increasing the risk of account compromise. Organizations utilizing AVideo should prioritize addressing this vulnerability to safeguard user accounts against brute-force attacks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-86186
Severity
MEDIUM
CVSS
6.5
EPSS
0.18%

Original NVD Description

AVideo API fails to enforce rate limits when clients send a bot User-Agent header, allowing attackers to bypass all eight protected operations including login brute-force protection. Attackers can send requests with a bot User-Agent to disable rate limiting and perform unlimited password guessing attempts against any account from a single IP address.