Authentication Bypass in Studio-Saelix Sencho via X-Forwarded-For Manipulation
Studio-Saelix Sencho versions up to 0.94.1 contain an authentication bypass vulnerability (CVE-2026-108522) where improper processing of the X-Forwarded-For header allows remote attackers to circumvent login rate limits.
CVE search metadata
CVE search record: CVE-2026-108522. Severity: high. CVSS: 8.3. KEV: no. Product: Sencho (<= 0.94.1). Brief: Authentication Bypass in Studio-Saelix Sencho via X-Forwarded-For Manipulation. Brief link: https://feed.craftedsignal.io/briefs/2026-10-cve-2026-108522/
Studio-Saelix Sencho versions up to 0.94.1 contain a high-severity authentication bypass vulnerability (CVE-2026-108522) within the /api/auth/login endpoint. The flaw originates from the application's reliance on client-supplied X-Forwarded-For HTTP headers for login rate-limiting logic without enforcing a trusted-proxy boundary. Remote attackers can manipulate this header to rotate their apparent source IP address, effectively bypassing security controls designed to mitigate brute-force or credential-stuffing attacks. The vulnerability was publicly disclosed, and exploits are available, increasing the risk of abuse against internet-facing deployments. The vendor has addressed this in a patch by defaulting to ignoring forwarding headers, implementing strict CIDR-based trust boundaries for proxy headers, and anchoring account-identity-based limits.
Impact
Successful exploitation allows remote attackers to circumvent rate-limiting mechanisms, facilitating automated credential-stuffing or brute-force attacks against user accounts. This potentially leads to unauthorized account access and potential data exfiltration or account takeovers in environments where Sencho handles authentication.
Recommendation
- Upgrade Studio-Saelix Sencho to the latest version that includes commit 79b86ddcd4aefdd6941f098e35990ab397b13c72 to remediate CVE-2026-108522.
- Implement a trusted-proxy boundary at the load balancer or reverse proxy level to strip or validate X-Forwarded-For headers before they reach the application.
- Monitor web application logs for high volumes of login attempts originating from varying IP addresses mapped to the same account identifier.
Immediate actions
Upgrade Sencho to the latest patched version.
Threat Hunt
Identify spikes in failed login attempts for single accounts where the source IP address in the log entry differs significantly from the upstream connection metadata.
Data: webserver access logs
Mitigations
Configure the perimeter proxy to strip X-Forwarded-For headers from untrusted sources.
CVE-2026-108522