Skip to content
Threat Feed
high advisory

Authentication Bypass in Studio-Saelix Sencho via X-Forwarded-For Manipulation

Studio-Saelix Sencho versions up to 0.94.1 contain an authentication bypass vulnerability (CVE-2026-108522) where improper processing of the X-Forwarded-For header allows remote attackers to circumvent login rate limits.

CVE search metadata

CVE search record: CVE-2026-108522. Severity: high. CVSS: 8.3. KEV: no. Product: Sencho (<= 0.94.1). Brief: Authentication Bypass in Studio-Saelix Sencho via X-Forwarded-For Manipulation. Brief link: https://feed.craftedsignal.io/briefs/2026-10-cve-2026-108522/

Studio-Saelix Sencho versions up to 0.94.1 contain a high-severity authentication bypass vulnerability (CVE-2026-108522) within the /api/auth/login endpoint. The flaw originates from the application's reliance on client-supplied X-Forwarded-For HTTP headers for login rate-limiting logic without enforcing a trusted-proxy boundary. Remote attackers can manipulate this header to rotate their apparent source IP address, effectively bypassing security controls designed to mitigate brute-force or credential-stuffing attacks. The vulnerability was publicly disclosed, and exploits are available, increasing the risk of abuse against internet-facing deployments. The vendor has addressed this in a patch by defaulting to ignoring forwarding headers, implementing strict CIDR-based trust boundaries for proxy headers, and anchoring account-identity-based limits.

Impact

Successful exploitation allows remote attackers to circumvent rate-limiting mechanisms, facilitating automated credential-stuffing or brute-force attacks against user accounts. This potentially leads to unauthorized account access and potential data exfiltration or account takeovers in environments where Sencho handles authentication.

Recommendation

  • Upgrade Studio-Saelix Sencho to the latest version that includes commit 79b86ddcd4aefdd6941f098e35990ab397b13c72 to remediate CVE-2026-108522.
  • Implement a trusted-proxy boundary at the load balancer or reverse proxy level to strip or validate X-Forwarded-For headers before they reach the application.
  • Monitor web application logs for high volumes of login attempts originating from varying IP addresses mapped to the same account identifier.

Immediate actions

Upgrade Sencho to the latest patched version.

IT Operations 48h

Threat Hunt

Identify spikes in failed login attempts for single accounts where the source IP address in the log entry differs significantly from the upstream connection metadata.

T1595 medium medium confidence hunt now

Data: webserver access logs

Mitigations

Configure the perimeter proxy to strip X-Forwarded-For headers from untrusted sources.

immediate IT Operations

CVE-2026-108522