CVE-2026-108522 | Studio-Saelix Sencho up to 0.94.1 Login Endpoint /api/auth/login X-Forwarded-For improper authentication
A vulnerability identified as critical has been detected in Studio-Saelix Sencho up to 0.94.1. This affects an unknown part of the file /api/auth/login of the component Login Endpoint. Performing a manipulation of the argument X-Forwarded-For results in improper authentication.
This vulnerability is reported as CVE-2026-108522. The attack is possible to be carried out remotely. Moreover, an exploit is present.
To fix this issue, it is recommended to deploy a patch.
The vendor confirms: “The login limiter relied on client-supplied X-Forwarded-For data without an explicit trusted-proxy boundary, allowing an attacker to rotate the apparent client address. The remediation now ignores forwarding headers by default, accepts them only from explicitly configured proxy CIDRs, and adds a separate failed-attempt limit keyed by normalized account identity.”VulDB Recent EntriesRead More