Executive brief
The Stop Administrator Login module for Drupal is designed to prevent administrative users from logging in, but fails to enforce this restriction consistently across all authentication methods. An attacker with valid administrator credentials could bypass the block by using alternative authentication mechanisms, potentially gaining unauthorized administrative access to the website.
Technical details
The module does not uniformly enforce access restrictions for blocked administrative users (user 1 or users with the administrator role) across all supported authentication mechanisms, allowing authentication bypass through less common authentication methods. The attack requires valid administrative credentials and use of an alternative authentication path. A fix is available in version 1.6.0 and later.
Affected products
- Drupal Stop Administrator Login 1.0 to 1.5.x
Timeline
- 2026-09-23: disclosed
- 2026-09-23: patched