Ad

CVE-2026-39880

MEDIUM CVSS 3.1: 4.9 EPSS 0.03%
Updated Apr 17, 2026
Remnawave
Parameter Value
CVSS 4.9 (MEDIUM)
Affected Versions before 2.7.4
Fixed In 2.7.5
Type CWE-362 (Race Condition)
Vendor Remnawave
Public PoC No

Remnawave Backend is the backend for the Remnawave proxy and user management solution. Prior to 2.7.5, a glitch in the HWID device registration logic allows an authenticated user to bypass the configured limit for HWID devices and register more devices than expected, allowing them to resell subscriptions and consume excessive traffic. This vulnerability is fixed in 2.7.5.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
High
Difficult to exploit
Privileges Required
Low
Basic privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
None
No data leak
Integrity
Low
Partial data modification
Availability
Low
Partial disruption

CVSS Vector v3.1

Weakness Type (CWE)

Vulnerable Products 1

Configuration From (including) Up to (excluding)
Remnawave Remnawave_Backend
cpe:2.3:a:remnawave:remnawave_backend:*:*:*:*:*:*:*:*
<= 2.7.4