Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-39880

20
FAUCET Score

CVE-2026-39880 is a device registration bypass vulnerability affecting Remnawave Backend versions prior to 2.7.5. The flaw allows authenticated users to circumvent configured Hardware ID (HWID) device limits, enabling them to register more devices than permitted. This capability facilitates subscription reselling and excessive traffic consumption, undermining access controls within the Remnawave proxy and user management solution. The vulnerability carries a CVSS 3.1 severity rating of 4.9 (Medium), with a network-based attack vector requiring low authentication privileges and moderate complexity to exploit. The impact is limited to integrity and availability concerns rather than confidentiality breaches, with a modified scope indicating potential effects on other connected systems. Exploitation status remains low, with no evidence of active exploitation in the wild or public exploit code availability. The vulnerability is not listed on the Known Exploited Vulnerabilities (KEV) catalog and remains inactive on the Hot List, indicating minimal community attention or threat actor interest at this time. Organizations running Remnawave Backend should prioritize upgrading to version 2.7.5 to remediate this access control vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
<= 2.7.4CPE matchmatch criteria
cpe:2.3:a:remnawave:remnawave_backend:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.0MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
NONE
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
3.1
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.18%
Probability of exploitation in next 30 days
EPSS Percentile
8.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0018 is in the 6th percentile among its peer group of 1,425 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (1)

github_advisoryvendor investigatingvia nvd_reference
View patch

References

github.com / remnawave/backend/security/advisories/GHSA-985p-44h5-v3pq
ExploitVendor Advisory