๐Ÿ” CVE Alert

CVE-2026-1917

MEDIUM 4.3

Login Disable - Less critical - Access bypass - SA-CONTRIB-2026-008

CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
15th

Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Login Disable allows Functionality Bypass.This issue affects Login Disable: from 0.0.0 before 2.1.3.

CWE CWE-288
Vendor drupal
Product login disable
Ecosystems
Industries
WebMedia
Published Mar 25, 2026
Last Updated Mar 26, 2026
Stay Ahead of the Next One

Get instant alerts for drupal login disable

Be the first to know when new medium vulnerabilities affecting drupal login disable are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Drupal / Login Disable
0.0.0 < 2.1.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
drupal.org: https://www.drupal.org/sa-contrib-2026-008

Credits

Pierre Rudloff (prudloff) Boris Doesborg (batigolix) Pierre Rudloff (prudloff) Greg Knaddison (greggles) Juraj Nemec (poker10) Pierre Rudloff (prudloff)