CVE-2026-108580 PUBLISHED

AniWorld Downloader before 5.3.0 WebUI Login Brute Force via /login

Assigner: VulnCheck
Reserved: 10.10.2026 Published: 10.10.2026 Updated: 10.10.2026

AniWorld Downloader before 5.3.0 contains an improper restriction of authentication attempts vulnerability in the WebUI /login POST handler that allows unauthenticated attackers to guess passwords without throttling. Attackers can enumerate usernames through verify_user response timing and brute-force passwords on exposed WebUI instances to take over accounts.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
CVSS Score: 6.9

Product Status

Vendor phoenixthrush
Product AniWorld Downloader
Versions Default: unaffected
  • affected from 0 to 5.3.0 (excl.)

Credits

  • SiroxCW finder
  • HaiND from the Post and Telecommunication Institute of Technology finder

References

Problem Types

  • Improper Restriction of Excessive Authentication Attempts CWE