Executive brief
BiHayat is a municipal application used by residents of Bahçelievler to access local government services. The app fails to properly limit login attempts, allowing attackers to bypass authentication and gain unauthorized access to user accounts without requiring correct credentials. This could expose personal information, municipal records, and allow fraudulent transactions or service requests on behalf of legitimate users.
Technical details
The vulnerability is an improper restriction of excessive authentication attempts, enabling authentication bypass in BiHayat versions 2.1.7 through 07092026. An attacker can exploit the lack of rate limiting or account lockout mechanisms on the authentication endpoint to conduct brute-force or credential-stuffing attacks over the network without authentication prerequisites. Successful exploitation allows unauthorized access to user accounts and associated data. The vendor was contacted early but did not respond, and no patch status is currently known.
Affected products
- Bahçelievler Municipality BiHayat App 2.1.7 through 07092026
Timeline
- 2026-09-07: disclosed