CVE-2026-102248 PUBLISHED

Rebuild Login Endpoint login improper authentication

Assigner: VulDB
Reserved: 28.09.2026 Published: 29.09.2026 Updated: 29.09.2026

A vulnerability was identified in Rebuild up to 4.4.7/4.5.0-beta5. This affects an unknown part of the file /user/login of the component Login Endpoint. The manipulation leads to improper authentication. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
CVSS Score: 6.9

Product Status

Vendor n/a
Product Rebuild
Versions
  • Version 4.4.0 is affected
  • Version 4.4.1 is affected
  • Version 4.4.2 is affected
  • Version 4.4.3 is affected
  • Version 4.4.4 is affected
  • Version 4.4.5 is affected
  • Version 4.4.6 is affected
  • Version 4.4.7 is affected
  • Version 4.5.0-beta1 is affected
  • Version 4.5.0-beta2 is affected
  • Version 4.5.0-beta3 is affected
  • Version 4.5.0-beta4 is affected
  • Version 4.5.0-beta5 is affected

Credits

  • asants (VulDB User) reporter
  • VulDB CNA Team coordinator

References

Problem Types

  • Improper Authentication CWE