AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-108580.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSMEDIUM / 6.9CVSS 4.0 · disclosure@vulncheck.com
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSReceivedModified Oct 10, 2026

Disclosure summary

AniWorld Downloader before 5.3.0 contains an improper restriction of authentication attempts vulnerability in the WebUI /login POST handler that allows unauthenticated attackers to guess passwords without throttling. Attackers can enumerate usernames through verify_user response timing and brute-force passwords on exposed WebUI instances to take over accounts.

Source-reported weakness categories

CWE-307

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

CVEProject/cvelistV5 releases · RSS-6729502a4ea3125ddd379f75d3eb8cb63a6

Open original source · Updated Oct 10, 2026

CVE 2026-10-10_1700Z

CVE mention in publisher metadata; check the original affected versions.

CVEProject/cvelistV5 releases · RSS-a10ecc85ff20aad80a7e8436dd92befdcfc

Open original source · Updated Oct 10, 2026

CVE 2026-10-10_1600Z

CVE mention in publisher metadata; check the original affected versions.

NIST National Vulnerability Database · NVD-CVE-2026-108580

Open original source · Updated Oct 10, 2026

Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.

Original records & references

PUBLISHED 2026-10-10T12:16:31-04:00
MODIFIED 2026-10-10T12:16:31-04:00
INGESTED 2026-10-10T20:55:17-04:00