Project machine name: 
disable_login
Date: 
2026-August-26
Vulnerability: 
Access bypass
Affected versions: 
<1.1.4
CVE IDs: 
CVE-2026-18260
Description: 

This module enables you to disable access to the /user/login form unless a secret key is provided.

The module does not sufficiently restrict repeated attempts to guess that key, allowing brute-force attacks against the access-control mechanism.

Solution: 

Install the latest version:

Reported By: 
Coordinated By: