SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-18260

MEDIUM · CVSS 5.7 EPSS 0.22%

Source: NVD + CISA KEV + EPSS · Published 2026-08-25 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The vulnerability in the Disable Login Page module for Drupal allows unauthorized users to potentially bypass authentication mechanisms, compromising the security of the application. Organizations utilizing this module should prioritize remediation to prevent unauthorized access and protect sensitive data, especially those managing user authentication processes.

CVE
CVE-2026-18260
Severity
MEDIUM
CVSS
5.7
EPSS
0.22%

Original NVD Description

Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Disable Login Page allows Brute Force. This issue affects Disable Login Page versions: from 0.0.0 to 1.1.4.