Sceawere
Vulnerability Detail
CVE-2026-108580UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
AniWorld Downloader Authentication Bypass Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.5
- Creation Date
- 2h ago
- Vendor
- phoenixthrush
- Product
- AniWorld Downloader
- Attack Type
- Improper Restriction of Excessive Authentication Attempts
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
AniWorld Downloader before 5.3.0 contains an improper restriction of authentication attempts vulnerability in the WebUI /login POST handler that allows unauthenticated attackers to guess passwords without throttling. Attackers can enumerate usernames through verify_user response timing and brute-force passwords on exposed WebUI instances to take over accounts.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.5",
"pubDate": "2026-10-10T16:16:31.240Z",
"pubdate": "2026-10-10T16:16:31.240Z",
"executiveSummary": "AniWorld Downloader versions prior to 5.3.0 are susceptible to an improper restriction of authentication attempts within the WebUI /login POST handler.\nThe vulnerability stems from the absence of rate-limiting or account lockout mechanisms, enabling unauthenticated remote attackers to perform automated brute-force attacks against user credentials.\nFurthermore, the application exhibits differential timing behavior during the verification of usernames, allowing for user enumeration.\nSuccessful exploitation facilitates unauthorized account takeover, granting attackers full control over compromised sessions.\nThe risk is significantly elevated for instances exposed to public networks, as attackers can systematically guess passwords without encountering defensive obstacles.\nNo specific privileges are required for exploitation, as the flaw resides in the pre-authentication phase of the application lifecycle.\nThe lack of throttling and the observable timing side-channel collectively create a high-impact security risk for affected AniWorld Downloader deployments.",
"technicalDetails": "The vulnerability resides within the WebUI component of AniWorld Downloader, specifically targeting the /login POST request handler responsible for processing user authentication credentials.\nThe root cause is a fundamental failure to implement cryptographic or application-level rate limiting, allowing for unbounded authentication attempts. This configuration permits an attacker to submit high-frequency POST requests to verify credentials without triggering account lockouts or IP-based rate limiting.\nAn additional vector exists via a timing side-channel attack during the verify_user process. Because the server response time varies based on whether a submitted username exists in the internal database, an attacker can map valid user accounts through statistical analysis of latency metrics observed in HTTP responses.\nThe attack flow for password brute-forcing is as follows: 1) The attacker initiates repeated POST requests to the /login endpoint. 2) The server processes these requests synchronously without enforcing a request-per-second threshold. 3) The attacker iterates through large password wordlists. 4) The server returns distinct responses for incorrect passwords, allowing the attacker to identify valid credentials without disruption.\nThe exploitation of the user enumeration vector involves: 1) Sending targeted requests to the verify_user function for various account identifiers. 2) Measuring the delta in response time between valid and invalid usernames. 3) Utilizing these timing differentials to confirm the existence of specific accounts within the system.\nThis vulnerability is classified as critical due to its potential for total system compromise when the WebUI is exposed over public networks. The lack of throttling mechanisms facilitates the automated testing of entire credential dictionaries, effectively neutralizing basic password security measures. Post-exploitation impact includes unauthorized access to user-specific settings, downloads, and administrative functionality if the compromised account possesses elevated permissions. The vulnerability exists until the implementation of a robust authentication management system that incorporates both request throttling and consistent-time comparison logic for user verification."
}