THREAT OPS › Threat News › [NVD] CVE-2026-86186 (MEDIUM 6.5) — AVideo API fails to enforce rate limits when clients send a bot User-Agent header, allowing attackers to bypass all eight protected operations including login brute-force protection. Attackers can send requests with a bot User-Agent to disable rate limiting and perform unlimited
[NVD] CVE-2026-86186 (MEDIUM 6.5) — AVideo API fails to enforce rate limits when clients send a bot User-Agent header, allowing attackers to bypass all eight protected operations including login brute-force protection. Attackers can send requests with a bot User-Agent to disable rate limiting and perform unlimited
CVE-2026-86186 CVSS: 6.5 MEDIUM Published: 2026-09-05T13:18:13.560
AVideo API fails to enforce rate limits when clients send a bot User-Agent header, allowing attackers to bypass all eight protected operations including login brute-force protection. Attackers can send requests with a bot User-Agent to disable rate limiting and perform unlimited password guessing attempts against any account from
MITRE ATT&CK techniques
- Password GuessingT1110.001
Indicators of compromise
- CVE-2026-86186cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-86186