AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2024-6832

MEDIUM · CVSS 5.9 EPSS 0.24% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-06 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The vulnerability arises from a failure in the account locking mechanism when secondary user stores are inaccessible, allowing attackers to bypass lockout protections. This oversight enables brute force attacks on user accounts within active stores, as invalid authentication attempts do not trigger the expected lockout. Organizations utilizing systems with multiple user stores should prioritize addressing this vulnerability to safeguard against unauthorized access.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2024-6832
Severity
MEDIUM
CVSS
5.9
EPSS
0.24%

Original NVD Description

The account locking mechanism fails to trigger when secondary user stores are inaccessible. The software does not maintain a consistent state for account locking if it cannot reach all configured user stores, allowing an attacker to repeatedly attempt authentication with invalid credentials without triggering the lockout mechanism for users within active stores. When the account locking mechanism is bypassed due to the inaccessibility of secondary user stores, users in accessible user stores are left vulnerable to brute force attacks. A malicious actor can exploit this by attempting numerous invalid password combinations against a user account without the expected account lockout consequence.

Related CVEs

Other vulnerabilities affecting the same vendor(s)