Junglewise Threat Intelligence

CVE-2026-15079: Drupal Login Disable brute force vulnerability in secret key protection

CVE-2026-15079 · Severity: info · CVSS 5.4 · Published 2026-07-10

Technologies: Packagist:Https://Packages.Drupal.Org/8 Drupal/Login Disable. Vendors: Packagist:Https://Packages.Drupal.Org/8, Drupal.

Executive brief

The Login Disable module for Drupal is used to hide the login page behind a secret URL key to prevent unauthorized access. A security flaw allows attackers to repeatedly guess this secret key without being blocked, potentially allowing them to reach the login form. If an attacker successfully guesses the key and possesses valid user credentials, they could bypass the intended security restrictions of the module.

Technical details

The Login Disable module (versions prior to 2.1.4) contains an 'Improper Restriction of Excessive Authentication Attempts' (CWE-307) vulnerability. The module's mechanism for protecting the login form via a secret URL parameter did not implement flood control or rate limiting. This allows a remote attacker to perform a brute-force attack to discover the secret key. While an attacker still requires valid user credentials to log in, discovering the key bypasses the primary access control provided by this module. The vulnerability is resolved in version 2.1.4 by implementing Drupal's flood control API to block excessive attempts.

Affected products

  • Drupal Login Disable 0.0.0 to 2.1.3

Timeline

  • 2026-07-07: patched: Version 2.1.4 released
  • 2026-07-08: advisory: Drupal security advisory SA-CONTRIB-2026-070 published
  • 2026-07-10: disclosed: CVE-2026-15079 published to NVD

References

Related threats