{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3astudio_saelixsencho/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:studio_saelix:sencho:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.3,"id":"CVE-2026-108522"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Sencho (\u003c= 0.94.1)"],"_cs_severities":["high"],"_cs_tags":["web-application-vulnerability","authentication-bypass","cve-2026-108522"],"_cs_type":"advisory","_cs_vendors":["Studio-Saelix"],"content_html":"\u003cp\u003eStudio-Saelix Sencho versions up to 0.94.1 contain a high-severity authentication bypass vulnerability (CVE-2026-108522) within the /api/auth/login endpoint. The flaw originates from the application's reliance on client-supplied X-Forwarded-For HTTP headers for login rate-limiting logic without enforcing a trusted-proxy boundary. Remote attackers can manipulate this header to rotate their apparent source IP address, effectively bypassing security controls designed to mitigate brute-force or credential-stuffing attacks. The vulnerability was publicly disclosed, and exploits are available, increasing the risk of abuse against internet-facing deployments. The vendor has addressed this in a patch by defaulting to ignoring forwarding headers, implementing strict CIDR-based trust boundaries for proxy headers, and anchoring account-identity-based limits.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows remote attackers to circumvent rate-limiting mechanisms, facilitating automated credential-stuffing or brute-force attacks against user accounts. This potentially leads to unauthorized account access and potential data exfiltration or account takeovers in environments where Sencho handles authentication.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade Studio-Saelix Sencho to the latest version that includes commit 79b86ddcd4aefdd6941f098e35990ab397b13c72 to remediate CVE-2026-108522.\u003c/li\u003e\n\u003cli\u003eImplement a trusted-proxy boundary at the load balancer or reverse proxy level to strip or validate X-Forwarded-For headers before they reach the application.\u003c/li\u003e\n\u003cli\u003eMonitor web application logs for high volumes of login attempts originating from varying IP addresses mapped to the same account identifier.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-11T05:59:02Z","date_published":"2026-10-11T05:59:02Z","id":"https://feed.craftedsignal.io/briefs/2026-10-cve-2026-108522/","summary":"Studio-Saelix Sencho versions up to 0.94.1 contain an authentication bypass vulnerability (CVE-2026-108522) where improper processing of the X-Forwarded-For header allows remote attackers to circumvent login rate limits.","title":"Authentication Bypass in Studio-Saelix Sencho via X-Forwarded-For Manipulation","url":"https://feed.craftedsignal.io/briefs/2026-10-cve-2026-108522/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:studio_saelix:sencho:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}