๐Ÿ” CVE Alert

CVE-2026-18260

MEDIUM 5.7

Disable Login Page - Moderately critical - Access bypass - SA-CONTRIB-2026-110

CVSS Score
5.7
EPSS Score
0.0%
EPSS Percentile
0th

Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Disable Login Page allows Brute Force. This issue affects Disable Login Page versions: from 0.0.0 to 1.1.4.

CWE CWE-307
Vendor drupal
Product disable login page
Ecosystems
Industries
WebMedia
Published Aug 25, 2026
Last Updated Sep 2, 2026
Stay Ahead of the Next One

Get instant alerts for drupal disable login page

Be the first to know when new medium vulnerabilities affecting drupal disable login page are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Drupal / Disable Login Page
0.0.0 < 1.1.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
drupal.org: https://www.drupal.org/sa-contrib-2026-110

Credits

Pierre Rudloff (prudloff) Brian Osborne (bkosborne) Jason Partyka (partyka) Neil Drumm (drumm) Greg Knaddison (greggles) Dave Long (longwave) Juraj Nemec (poker10) Pierre Rudloff (prudloff) Jess (xjm)