CVE-2026-39880 is a device registration bypass vulnerability affecting Remnawave Backend versions prior to 2.7.5. The flaw allows authenticated users to circumvent configured Hardware ID (HWID) device limits, enabling them to register more devices than permitted. This capability facilitates subscription reselling and excessive traffic consumption, undermining access controls within the Remnawave proxy and user management solution. The vulnerability carries a CVSS 3.1 severity rating of 4.9 (Medium), with a network-based attack vector requiring low authentication privileges and moderate complexity to exploit. The impact is limited to integrity and availability concerns rather than confidentiality breaches, with a modified scope indicating potential effects on other connected systems. Exploitation status remains low, with no evidence of active exploitation in the wild or public exploit code availability. The vulnerability is not listed on the Known Exploited Vulnerabilities (KEV) catalog and remains inactive on the Hot List, indicating minimal community attention or threat actor interest at this time. Organizations running Remnawave Backend should prioritize upgrading to version 2.7.5 to remediate this access control vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.7.4CPE matchmatch criteria | cpe:2.3:a:remnawave:remnawave_backend:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.