Junglewise Threat Intelligence

CVE-2026-19898: VictoriaMetrics VMAuth brute-force attack mitigation bypass

CVE-2026-19898 · Severity: low · CVSS 3.7 · Published 2026-08-15

Executive brief

VictoriaMetrics VMAuth is an authentication proxy component used to control access to monitoring systems. The vulnerability allows attackers to bypass authentication protections and perform brute-force attacks against user credentials at scale, potentially compromising access to sensitive monitoring data and operational systems.

Technical details

The vulnerability is an improper restriction of excessive authentication attempts (lack of rate limiting/delay mitigation) in the VMAuth authentication endpoint's requestHandler function. An attacker can send thousands of authentication requests per second with minimal cost to brute-force valid credentials. The attack is network-accessible with high complexity and difficult exploitability. The fix (commit 119ba0fb5be8024d50c5ba946599b2e69e8803ea) adds a random 2–3 second delay before returning 401 Unauthorized responses to slow down brute-force attacks while minimally impacting legitimate users. Upgrading to version 1.147.0 or later addresses this issue.

Affected products

  • VictoriaMetrics VictoriaMetrics up to 1.146.0

Timeline

  • 2026-08-15: disclosed
  • 2026-08-15: patched: patch 119ba0fb5be8024d50c5ba946599b2e69e8803ea available in version 1.147.0

References

Related threats