Executive brief
The Login Disable module for Drupal is used to hide the login page behind a secret URL key to prevent unauthorized access. A security flaw allows attackers to repeatedly guess this secret key without being blocked, potentially allowing them to reach the login form. If an attacker successfully guesses the key and possesses valid user credentials, they could bypass the intended security restrictions of the module.
Technical details
The Login Disable module (versions prior to 2.1.4) contains an 'Improper Restriction of Excessive Authentication Attempts' (CWE-307) vulnerability. The module's mechanism for protecting the login form via a secret URL parameter did not implement flood control or rate limiting. This allows a remote attacker to perform a brute-force attack to discover the secret key. While an attacker still requires valid user credentials to log in, discovering the key bypasses the primary access control provided by this module. The vulnerability is resolved in version 2.1.4 by implementing Drupal's flood control API to block excessive attempts.
Affected products
- Drupal Login Disable 0.0.0 to 2.1.3
Timeline
- 2026-07-07: patched: Version 2.1.4 released
- 2026-07-08: advisory: Drupal security advisory SA-CONTRIB-2026-070 published
- 2026-07-10: disclosed: CVE-2026-15079 published to NVD