Executive brief
The Disable Login Page module is a Drupal security extension that restricts access to the login form by requiring a secret key. The module fails to limit repeated login attempts, allowing attackers to brute force the secret key and gain unauthorized access to the login page on affected sites.
Technical details
This is a brute force vulnerability (CWE-307: Improper Restriction of Excessive Authentication Attempts) in the Disable Login Page module's access control mechanism. The module protects /user/login with a query string parameter containing a secret key-value pair, but lacks rate limiting or attempt restrictions. An unauthenticated attacker on the network can repeatedly guess the key without throttling, allowing brute force enumeration of valid keys. The vulnerability affects versions prior to 1.1.4, and was patched in version 1.1.4 released 2026-08-26.
Affected products
- Drupal Disable Login Page before 1.1.4
Timeline
- 2026-08-26: disclosed
- 2026-08-26: patched: Version 1.1.4 released with fix