Project:
Project machine name:
disable_loginDate:
2026-August-26
Vulnerability:
Access bypass
Affected versions:
<1.1.4
CVE IDs:
CVE-2026-18260
Description:
This module enables you to disable access to the /user/login form unless a secret key is provided.
The module does not sufficiently restrict repeated attempts to guess that key, allowing brute-force attacks against the access-control mechanism.
Solution:
Install the latest version:
- If you use the Disable Login Page module, upgrade to Disable Login Page 1.1.4.
Reported By:
- Pierre Rudloff (prudloff) of the Drupal Security Team
Coordinated By:
- Neil Drumm (drumm) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Dave Long (longwave) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team
- Pierre Rudloff (prudloff) of the Drupal Security Team
- Jess (xjm) of the Drupal Security Team