Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Not in CISA KEV

CVE-2018-8715 — Embedthis

CVE-2018-8715 is a Improper Authentication vulnerability. 1 public exploit reference exists, so weaponization risk is real. No vendor fix is recorded yet; mitigation options are listed below.

The Embedthis HTTP library, and Appweb versions before 7.0.3, have a logic flaw related to the authCondition function in http/httpLib.c. With a forged HTTP request, it is possible to…

Published
Updated
Affected
1 product
Patched
See advisory
Exploits
1 known
Exploitation data as of Oct 7, 2026 · OSV.dev, NVD, FIRST.org (EPSS)

EPSS Exploitation Probability

via FIRST.org ↗
22.8%probability of exploitation in next 30 days
Moderate Risk0.00%
Lower risk than most CVEs98th percentile — riskier than 98% of all scored CVEsHighest risk
0.00%33.3%66.7%100.0%92.3%22.8%Apr 26Aug 26Oct 26

Probability of exploitation in the next 30 days, from FIRST.org EPSS.

Description

The Embedthis HTTP library, and Appweb versions before 7.0.3, have a logic flaw related to the authCondition function in http/httpLib.c. With a forged HTTP request, it is possible to bypass authentication for the form and digest login types.

Affected Products

1 product · 1 configurations
Application
appwebembedthis
≤ 7.0.2
range
Exploits & PoCs
1

Research use only. For defensive security, authorized penetration testing, and academic research only. Never execute exploit code against systems without explicit written authorization.

Detection & mitigation playbook

Vulnerability
  1. Detect

    Identify every host running the affected component and compare the installed build against the fixed version below — for source-built or distro-packaged software the version string, not a lockfile, is the source of truth (`dpkg -l`, `rpm -q`, or the binary's own `--version`).

  2. Remediation status

    No fixed release is recorded for CVE-2018-8715 yet. Track the upstream advisory, and apply the exposure-reduction steps below in the meantime.

  3. Mitigate without a patch

    Put an independent control in front of the weakness: restrict the affected endpoint or interface to trusted networks, require an additional authentication factor or proxy-level check, and invalidate existing sessions and credentials in case the flaw has already been used.

How to detect CVE-2018-8715

A community-maintained Nuclei template exists for this CVE. You can scan for it directly:

nuclei -id cve-2018-8715 -u https://target
Template
AppWeb - Authentication Bypass
Severity
high
Impact
Successful exploitation of this vulnerability could allow an attacker to bypass authentication and gain unauthorized access to the application.
Remediation
Apply the necessary patches or updates provided by the vendor to fix the authentication bypass vulnerability in AppWeb.

Template by ProjectDiscovery nuclei-templates (milo2012), MIT licensed. View the full template. Scan only systems you are authorised to test.

Frequently Asked Questions

The Embedthis HTTP library, and Appweb versions before 7.0.3, have a logic flaw related to the authCondition function in http/httpLib.c. With a forged HTTP request, it is possible to bypass authentication for the form and digest login types.
O3 Security · Impact-Aware SCA

Is CVE-2018-8715 in your dependencies?

Find it across , including transitive dependencies.

CVE-2018-8715: Embedthis