Sceawere

Vulnerability Detail

CVE-2026-108580UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

AniWorld Downloader Authentication Bypass Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
2h ago
Vendor
phoenixthrush
Product
AniWorld Downloader
Attack Type
Improper Restriction of Excessive Authentication Attempts
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

AniWorld Downloader before 5.3.0 contains an improper restriction of authentication attempts vulnerability in the WebUI /login POST handler that allows unauthenticated attackers to guess passwords without throttling. Attackers can enumerate usernames through verify_user response timing and brute-force passwords on exposed WebUI instances to take over accounts.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-10-10T16:16:31.240Z",
  "pubdate": "2026-10-10T16:16:31.240Z",
  "executiveSummary": "AniWorld Downloader versions prior to 5.3.0 are susceptible to an improper restriction of authentication attempts within the WebUI /login POST handler.\nThe vulnerability stems from the absence of rate-limiting or account lockout mechanisms, enabling unauthenticated remote attackers to perform automated brute-force attacks against user credentials.\nFurthermore, the application exhibits differential timing behavior during the verification of usernames, allowing for user enumeration.\nSuccessful exploitation facilitates unauthorized account takeover, granting attackers full control over compromised sessions.\nThe risk is significantly elevated for instances exposed to public networks, as attackers can systematically guess passwords without encountering defensive obstacles.\nNo specific privileges are required for exploitation, as the flaw resides in the pre-authentication phase of the application lifecycle.\nThe lack of throttling and the observable timing side-channel collectively create a high-impact security risk for affected AniWorld Downloader deployments.",
  "technicalDetails": "The vulnerability resides within the WebUI component of AniWorld Downloader, specifically targeting the /login POST request handler responsible for processing user authentication credentials.\nThe root cause is a fundamental failure to implement cryptographic or application-level rate limiting, allowing for unbounded authentication attempts. This configuration permits an attacker to submit high-frequency POST requests to verify credentials without triggering account lockouts or IP-based rate limiting.\nAn additional vector exists via a timing side-channel attack during the verify_user process. Because the server response time varies based on whether a submitted username exists in the internal database, an attacker can map valid user accounts through statistical analysis of latency metrics observed in HTTP responses.\nThe attack flow for password brute-forcing is as follows: 1) The attacker initiates repeated POST requests to the /login endpoint. 2) The server processes these requests synchronously without enforcing a request-per-second threshold. 3) The attacker iterates through large password wordlists. 4) The server returns distinct responses for incorrect passwords, allowing the attacker to identify valid credentials without disruption.\nThe exploitation of the user enumeration vector involves: 1) Sending targeted requests to the verify_user function for various account identifiers. 2) Measuring the delta in response time between valid and invalid usernames. 3) Utilizing these timing differentials to confirm the existence of specific accounts within the system.\nThis vulnerability is classified as critical due to its potential for total system compromise when the WebUI is exposed over public networks. The lack of throttling mechanisms facilitates the automated testing of entire credential dictionaries, effectively neutralizing basic password security measures. Post-exploitation impact includes unauthorized access to user-specific settings, downloads, and administrative functionality if the compromised account possesses elevated permissions. The vulnerability exists until the implementation of a robust authentication management system that incorporates both request throttling and consistent-time comparison logic for user verification."
}
CVE-2026-108580: AniWorld Downloader Authentication Bypass Vulnerability (MEDIUM Severity, CVSS: 6.5) | Sceawere