CVE-2026-16647 PUBLISHED

Disable Login Page - Moderately critical - Access bypass - SA-CONTRIB-2026-111

Assigner: drupal
Reserved: 22.07.2026 Published: 02.09.2026 Updated: 02.09.2026

Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Disable Login Page allows Functionality Bypass. This issue affects Disable Login Page versions: from 0.0.0 to 1.1.4.

Product Status

Vendor Drupal
Product Disable Login Page
Versions
  • affected from 0.0.0 to 1.1.4 (excl.)

Credits

  • Brian Osborne (bkosborne) finder
  • Jason Partyka (partyka) finder
  • Brian Osborne (bkosborne) remediation developer
  • Jason Partyka (partyka) remediation developer
  • Greg Knaddison (greggles) coordinator
  • Juraj Nemec (poker10) coordinator
  • Pierre Rudloff (prudloff) coordinator
  • Jess (xjm) coordinator

References

Problem Types

  • CWE-288 Authentication Bypass Using an Alternate Path or Channel CWE

Impacts

  • CAPEC-554 Functionality Bypass