CWE-307
AllowedImproper Restriction of Excessive Authentication Attempts
Abstraction: Base · Status: Draft
The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.
1024 vulnerabilities reference this CWE, most recent first.
CVE-2026-102825 (GCVE-0-2026-102825)
Vulnerability from cvelistv5 – Published: 2026-09-29 18:31 – Updated: 2026-09-30 19:29- CWE-307 - Improper Restriction of Excessive Authentication Attempts
| URL | Tags |
|---|---|
| https://github.com/Eugeny/russh/security/advisori… | x_refsource_CONFIRM |
| https://github.com/Eugeny/russh/commit/f8fd0b11a3… | x_refsource_MISC |
| https://github.com/Eugeny/russh/releases/tag/v0.62.6 | x_refsource_MISC |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-102825",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-30T19:29:11.461462Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T19:29:26.432Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://github.com/Eugeny/russh/security/advisories/GHSA-g6xm-f9xp-qq35"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "russh",
"vendor": "Eugeny",
"versions": [
{
"status": "affected",
"version": "\u003c 0.62.6"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Russh is a Rust SSH client and server library. Prior to 0.62.6, the USERAUTH_REQUEST path reached from server::run_stream in russh/src/server/encrypted.rs increments self.common.auth_attempts but never compares it with server::Config.max_auth_attempts. An unauthenticated remote client can continue submitting authentication requests on one connection beyond the configured cap, bypassing the deployment\u0027s attempt-limiting policy and increasing online guessing opportunity and backend authentication workload. This issue is fixed in version 0.62.6."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 3.7,
"baseSeverity": "LOW",
"confidentialityImpact": "LOW",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-307",
"description": "CWE-307: Improper Restriction of Excessive Authentication Attempts",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-29T18:31:32.393Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/Eugeny/russh/security/advisories/GHSA-g6xm-f9xp-qq35",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/Eugeny/russh/security/advisories/GHSA-g6xm-f9xp-qq35"
},
{
"name": "https://github.com/Eugeny/russh/commit/f8fd0b11a393364dc7f01a182482d86adafdd653",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/Eugeny/russh/commit/f8fd0b11a393364dc7f01a182482d86adafdd653"
},
{
"name": "https://github.com/Eugeny/russh/releases/tag/v0.62.6",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/Eugeny/russh/releases/tag/v0.62.6"
}
],
"source": {
"advisory": "GHSA-g6xm-f9xp-qq35",
"discovery": "UNKNOWN"
},
"title": "Russh: Configured server auth-attempt cap is not enforced in the USERAUTH_REQUEST runtime path"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-102825",
"datePublished": "2026-09-29T18:31:32.393Z",
"dateReserved": "2026-09-29T17:25:25.265Z",
"dateUpdated": "2026-09-30T19:29:26.432Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-102334 (GCVE-0-2026-102334)
Vulnerability from cvelistv5 – Published: 2026-09-28 22:21 – Updated: 2026-09-29 19:47- CWE-307 - Improper Restriction of Excessive Authentication Attempts
| URL | Tags |
|---|---|
| https://github.com/NginxProxyManager/nginx-proxy-… | patchissue-tracking |
| https://github.com/NginxProxyManager/nginx-proxy-… | technical-description |
| https://github.com/NginxProxyManager/nginx-proxy-… | technical-description |
| https://github.com/NginxProxyManager/nginx-proxy-… | technical-description |
| https://github.com/NginxProxyManager/nginx-proxy-… | product |
| https://www.vulncheck.com/advisories/nginx-proxy-… | third-party-advisory |
| Vendor | Product | Version | |
|---|---|---|---|
| NginxProxyManager | nginx-proxy-manager |
Affected:
0 , ≤ 2.16.0
(custom)
cpe:2.3:a:nginxproxymanager:nginx_proxy_manager:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-102334",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-29T19:47:02.219168Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-29T19:47:25.772Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:github/NginxProxyManager/nginx-proxy-manager",
"product": "nginx-proxy-manager",
"repo": "https://github.com/NginxProxyManager/nginx-proxy-manager",
"vendor": "NginxProxyManager",
"versions": [
{
"lessThanOrEqual": "2.16.0",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:nginxproxymanager:nginx_proxy_manager:*:*:*:*:*:*:*:*",
"versionEndIncluding": "2.16.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Lazizbek Djurayev (Haad TC)"
}
],
"datePublic": "2026-09-28T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Nginx Proxy Manager through 2.16.0 lacks rate-limiting on authentication endpoints, allowing unauthenticated attackers to make unlimited password guesses against any account. Attackers can brute-force login credentials via POST /api/tokens and subsequently guess TOTP codes via POST /api/tokens/2fa to gain full session access and administrative control."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "NETWORK",
"baseScore": 9.1,
"baseSeverity": "CRITICAL",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 7.4,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-307",
"description": "Improper Restriction of Excessive Authentication Attempts",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-28T22:21:41.072Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"tags": [
"patch",
"issue-tracking"
],
"url": "https://github.com/NginxProxyManager/nginx-proxy-manager/pull/5908"
},
{
"tags": [
"technical-description"
],
"url": "https://github.com/NginxProxyManager/nginx-proxy-manager/blob/v2.16.0/backend/app.js#L15-L58"
},
{
"tags": [
"technical-description"
],
"url": "https://github.com/NginxProxyManager/nginx-proxy-manager/blob/v2.16.0/backend/internal/token.js#L154-L182"
},
{
"tags": [
"technical-description"
],
"url": "https://github.com/NginxProxyManager/nginx-proxy-manager/blob/v2.16.0/backend/internal/2fa.js#L196-L240"
},
{
"tags": [
"product"
],
"url": "https://github.com/NginxProxyManager/nginx-proxy-manager"
},
{
"name": "VulnCheck Advisory: Nginx Proxy Manager through 2.16.0 Missing Brute-Force Protection",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/nginx-proxy-manager-through-2.16.0-missing-brute-force-protection"
}
],
"title": "Nginx Proxy Manager through 2.16.0 Missing Brute-Force Protection",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-102334",
"datePublished": "2026-09-28T22:21:41.072Z",
"dateReserved": "2026-09-28T22:08:55.547Z",
"dateUpdated": "2026-09-29T19:47:25.772Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-100678 (GCVE-0-2026-100678)
Vulnerability from cvelistv5 – Published: 2026-09-26 13:23 – Updated: 2026-09-30 15:00- CWE-307 - Improper Restriction of Excessive Authentication Attempts
| URL | Tags |
|---|---|
| https://github.com/stoatchat/stoatchat/security/a… | vendor-advisory |
| https://www.vulncheck.com/advisories/stoatchat-be… | third-party-advisory |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-100678",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-30T14:59:59.255314Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T15:00:30.440Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://github.com/stoatchat/stoatchat/security/advisories/GHSA-6877-g673-f5r8"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "stoatchat",
"vendor": "stoatchat",
"versions": [
{
"lessThan": "0.15.5",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "0.15.5",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "QuentinRa"
}
],
"datePublic": "2026-09-11T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "stoatchat before 0.15.5 fails to enforce account-level attempt limits on MFA login challenges, allowing attackers who know a password to guess TOTP codes with only IP-based rate limiting. Attackers can reuse MFA challenge tickets across multiple failed attempts and distribute guesses across IP addresses to bypass rate limiting and gain account access."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "HIGH",
"attackRequirements": "PRESENT",
"attackVector": "NETWORK",
"baseScore": 8.3,
"baseSeverity": "HIGH",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "LOW"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "HIGH",
"integrityImpact": "LOW",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-307",
"description": "Improper Restriction of Excessive Authentication Attempts",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-26T13:23:40.935Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Security Advisory (GHSA-6877-g673-f5r8)",
"tags": [
"vendor-advisory"
],
"url": "https://github.com/stoatchat/stoatchat/security/advisories/GHSA-6877-g673-f5r8"
},
{
"name": "VulnCheck Advisory: stoatchat before 0.15.5 MFA Brute Force via Insufficient Rate Limiting",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/stoatchat-before-0.15.5-mfa-brute-force-via-insufficient-rate-limiting"
}
],
"title": "stoatchat before 0.15.5 MFA Brute Force via Insufficient Rate Limiting",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-100678",
"datePublished": "2026-09-26T13:23:40.935Z",
"dateReserved": "2026-09-26T02:36:51.809Z",
"dateUpdated": "2026-09-30T15:00:30.440Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-100501 (GCVE-0-2026-100501)
Vulnerability from cvelistv5 – Published: 2026-09-25 22:04 – Updated: 2026-09-25 22:04- CWE-307 - Improper Restriction of Excessive Authentication Attempts
| URL | Tags |
|---|---|
| https://github.com/pawelmalak/flame/issues/494 | issue-tracking |
| https://github.com/pawelmalak/flame/blob/v2.4.0/r… | technical-description |
| https://github.com/pawelmalak/flame/blob/v2.4.0/c… | technical-description |
| https://github.com/pawelmalak/flame/blob/v2.4.0/.… | technical-description |
| https://github.com/pawelmalak/flame | product |
| https://www.vulncheck.com/advisories/flame-throug… | third-party-advisory |
| Vendor | Product | Version | |
|---|---|---|---|
| pawelmalak | flame |
Affected:
0 , ≤ 2.4.0
(custom)
|
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "flame",
"vendor": "pawelmalak",
"versions": [
{
"lessThanOrEqual": "2.4.0",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Whispergate Security Research"
}
],
"datePublic": "2026-08-17T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Flame through 2.4.0 contains an improper restriction of excessive authentication attempts vulnerability in the POST /api/auth login endpoint that allows unauthenticated attackers to brute-force the admin password. Attackers can submit unlimited password guesses without rate limiting, attempt counters, lockouts, or delays to gain full administrator access and modify application configuration."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "HIGH",
"attackRequirements": "PRESENT",
"attackVector": "NETWORK",
"baseScore": 8.3,
"baseSeverity": "HIGH",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "LOW",
"vulnIntegrityImpact": "HIGH"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-307",
"description": "Improper Restriction of Excessive Authentication Attempts",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-25T22:04:01.425Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Issue #494 (finding 1)",
"tags": [
"issue-tracking"
],
"url": "https://github.com/pawelmalak/flame/issues/494"
},
{
"name": "POST /api/auth registered with no rate limiting",
"tags": [
"technical-description"
],
"url": "https://github.com/pawelmalak/flame/blob/v2.4.0/routes/auth.js#L7"
},
{
"name": "login compares the single admin password and issues a JWT",
"tags": [
"technical-description"
],
"url": "https://github.com/pawelmalak/flame/blob/v2.4.0/controllers/auth/login.js#L11-L22"
},
{
"name": "Docker image default PASSWORD",
"tags": [
"technical-description"
],
"url": "https://github.com/pawelmalak/flame/blob/v2.4.0/.docker/Dockerfile#L28"
},
{
"tags": [
"product"
],
"url": "https://github.com/pawelmalak/flame"
},
{
"name": "VulnCheck Advisory: Flame through 2.4.0 Brute-Force Attack via Login Endpoint",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/flame-through-2.4.0-brute-force-attack-via-login-endpoint"
}
],
"title": "Flame through 2.4.0 Brute-Force Attack via Login Endpoint",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-100501",
"datePublished": "2026-09-25T22:04:01.425Z",
"dateReserved": "2026-09-25T21:39:02.327Z",
"dateUpdated": "2026-09-25T22:04:01.425Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-93650 (GCVE-0-2026-93650)
Vulnerability from cvelistv5 – Published: 2026-09-18 18:15 – Updated: 2026-09-18 19:47| URL | Tags |
|---|---|
| https://vuldb.com/vuln/407477 | vdb-entrytechnical-description |
| https://vuldb.com/vuln/407477/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-93650 | third-party-advisory |
| https://vuldb.com/submit/933655 | third-party-advisory |
| https://github.com/zast-ai/vulnerability-reports/… | exploit |
| https://github.com/saleor/saleor/issues/19203 | issue-tracking |
| https://github.com/saleor/saleor/ | product |
| Vendor | Product | Version | |
|---|---|---|---|
| n/a | Saleor |
Affected:
3.20.118
Affected: 3.21.0 Affected: 3.21.1 Affected: 3.21.2 Affected: 3.21.3 Affected: 3.21.4 Affected: 3.21.5 Affected: 3.21.6 Affected: 3.21.7 Affected: 3.21.8 Affected: 3.21.9 Affected: 3.21.10 Affected: 3.21.11 Affected: 3.21.12 Affected: 3.21.13 Affected: 3.21.14 Affected: 3.21.15 Affected: 3.21.16 Affected: 3.21.17 Affected: 3.21.18 Affected: 3.21.19 Affected: 3.21.20 Affected: 3.21.21 Affected: 3.21.22 Affected: 3.21.23 Affected: 3.21.24 Affected: 3.21.25 Affected: 3.21.26 Affected: 3.21.27 Affected: 3.21.28 Affected: 3.21.29 Affected: 3.21.30 Affected: 3.21.31 Affected: 3.21.32 Affected: 3.21.33 Affected: 3.21.34 Affected: 3.21.35 Affected: 3.21.36 Affected: 3.21.37 Affected: 3.21.38 Affected: 3.21.39 Affected: 3.21.40 Affected: 3.21.41 Affected: 3.21.42 Affected: 3.21.43 Affected: 3.21.44 Affected: 3.21.45 Affected: 3.21.46 Affected: 3.21.47 Affected: 3.21.48 Affected: 3.21.49 Affected: 3.21.50 Affected: 3.21.51 Affected: 3.21.52 Affected: 3.21.53 Affected: 3.21.54 Affected: 3.22.0 Affected: 3.22.1 Affected: 3.22.2 Affected: 3.22.3 Affected: 3.22.4 Affected: 3.22.5 Affected: 3.22.6 Affected: 3.22.7 Affected: 3.22.8 Affected: 3.22.9 Affected: 3.22.10 Affected: 3.22.11 Affected: 3.22.12 Affected: 3.22.13 Affected: 3.22.14 Affected: 3.22.15 Affected: 3.22.16 Affected: 3.22.17 Affected: 3.22.18 Affected: 3.22.19 Affected: 3.22.20 Affected: 3.22.21 Affected: 3.22.22 Affected: 3.22.23 Affected: 3.22.24 Affected: 3.22.25 Affected: 3.22.26 Affected: 3.22.27 Affected: 3.22.28 Affected: 3.22.29 Affected: 3.22.30 Affected: 3.22.31 Affected: 3.22.32 Affected: 3.22.33 Affected: 3.22.34 Affected: 3.22.35 Affected: 3.22.36 Affected: 3.22.37 Affected: 3.22.38 Affected: 3.22.39 Affected: 3.22.40 Affected: 3.22.41 Affected: 3.22.42 Affected: 3.22.43 Affected: 3.22.44 Affected: 3.22.45 Affected: 3.22.46 Affected: 3.22.47 Affected: 3.23.0 Affected: 3.23.1 Affected: 3.23.2 Affected: 3.23.3 Affected: 3.23.4 Affected: 3.23.5 Affected: 3.23.6 Affected: 3.23.7 Affected: 3.23.8 Affected: 3.23.9 Affected: 3.23.10 Affected: 3.23.11 Affected: 3.23.12 Affected: 3.23.13 Affected: 3.23.14 cpe:2.3:a:saleor:saleor:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-93650",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-18T19:47:42.986649Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-18T19:47:52.282Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:saleor:saleor:*:*:*:*:*:*:*:*"
],
"product": "Saleor",
"vendor": "n/a",
"versions": [
{
"status": "affected",
"version": "3.20.118"
},
{
"status": "affected",
"version": "3.21.0"
},
{
"status": "affected",
"version": "3.21.1"
},
{
"status": "affected",
"version": "3.21.2"
},
{
"status": "affected",
"version": "3.21.3"
},
{
"status": "affected",
"version": "3.21.4"
},
{
"status": "affected",
"version": "3.21.5"
},
{
"status": "affected",
"version": "3.21.6"
},
{
"status": "affected",
"version": "3.21.7"
},
{
"status": "affected",
"version": "3.21.8"
},
{
"status": "affected",
"version": "3.21.9"
},
{
"status": "affected",
"version": "3.21.10"
},
{
"status": "affected",
"version": "3.21.11"
},
{
"status": "affected",
"version": "3.21.12"
},
{
"status": "affected",
"version": "3.21.13"
},
{
"status": "affected",
"version": "3.21.14"
},
{
"status": "affected",
"version": "3.21.15"
},
{
"status": "affected",
"version": "3.21.16"
},
{
"status": "affected",
"version": "3.21.17"
},
{
"status": "affected",
"version": "3.21.18"
},
{
"status": "affected",
"version": "3.21.19"
},
{
"status": "affected",
"version": "3.21.20"
},
{
"status": "affected",
"version": "3.21.21"
},
{
"status": "affected",
"version": "3.21.22"
},
{
"status": "affected",
"version": "3.21.23"
},
{
"status": "affected",
"version": "3.21.24"
},
{
"status": "affected",
"version": "3.21.25"
},
{
"status": "affected",
"version": "3.21.26"
},
{
"status": "affected",
"version": "3.21.27"
},
{
"status": "affected",
"version": "3.21.28"
},
{
"status": "affected",
"version": "3.21.29"
},
{
"status": "affected",
"version": "3.21.30"
},
{
"status": "affected",
"version": "3.21.31"
},
{
"status": "affected",
"version": "3.21.32"
},
{
"status": "affected",
"version": "3.21.33"
},
{
"status": "affected",
"version": "3.21.34"
},
{
"status": "affected",
"version": "3.21.35"
},
{
"status": "affected",
"version": "3.21.36"
},
{
"status": "affected",
"version": "3.21.37"
},
{
"status": "affected",
"version": "3.21.38"
},
{
"status": "affected",
"version": "3.21.39"
},
{
"status": "affected",
"version": "3.21.40"
},
{
"status": "affected",
"version": "3.21.41"
},
{
"status": "affected",
"version": "3.21.42"
},
{
"status": "affected",
"version": "3.21.43"
},
{
"status": "affected",
"version": "3.21.44"
},
{
"status": "affected",
"version": "3.21.45"
},
{
"status": "affected",
"version": "3.21.46"
},
{
"status": "affected",
"version": "3.21.47"
},
{
"status": "affected",
"version": "3.21.48"
},
{
"status": "affected",
"version": "3.21.49"
},
{
"status": "affected",
"version": "3.21.50"
},
{
"status": "affected",
"version": "3.21.51"
},
{
"status": "affected",
"version": "3.21.52"
},
{
"status": "affected",
"version": "3.21.53"
},
{
"status": "affected",
"version": "3.21.54"
},
{
"status": "affected",
"version": "3.22.0"
},
{
"status": "affected",
"version": "3.22.1"
},
{
"status": "affected",
"version": "3.22.2"
},
{
"status": "affected",
"version": "3.22.3"
},
{
"status": "affected",
"version": "3.22.4"
},
{
"status": "affected",
"version": "3.22.5"
},
{
"status": "affected",
"version": "3.22.6"
},
{
"status": "affected",
"version": "3.22.7"
},
{
"status": "affected",
"version": "3.22.8"
},
{
"status": "affected",
"version": "3.22.9"
},
{
"status": "affected",
"version": "3.22.10"
},
{
"status": "affected",
"version": "3.22.11"
},
{
"status": "affected",
"version": "3.22.12"
},
{
"status": "affected",
"version": "3.22.13"
},
{
"status": "affected",
"version": "3.22.14"
},
{
"status": "affected",
"version": "3.22.15"
},
{
"status": "affected",
"version": "3.22.16"
},
{
"status": "affected",
"version": "3.22.17"
},
{
"status": "affected",
"version": "3.22.18"
},
{
"status": "affected",
"version": "3.22.19"
},
{
"status": "affected",
"version": "3.22.20"
},
{
"status": "affected",
"version": "3.22.21"
},
{
"status": "affected",
"version": "3.22.22"
},
{
"status": "affected",
"version": "3.22.23"
},
{
"status": "affected",
"version": "3.22.24"
},
{
"status": "affected",
"version": "3.22.25"
},
{
"status": "affected",
"version": "3.22.26"
},
{
"status": "affected",
"version": "3.22.27"
},
{
"status": "affected",
"version": "3.22.28"
},
{
"status": "affected",
"version": "3.22.29"
},
{
"status": "affected",
"version": "3.22.30"
},
{
"status": "affected",
"version": "3.22.31"
},
{
"status": "affected",
"version": "3.22.32"
},
{
"status": "affected",
"version": "3.22.33"
},
{
"status": "affected",
"version": "3.22.34"
},
{
"status": "affected",
"version": "3.22.35"
},
{
"status": "affected",
"version": "3.22.36"
},
{
"status": "affected",
"version": "3.22.37"
},
{
"status": "affected",
"version": "3.22.38"
},
{
"status": "affected",
"version": "3.22.39"
},
{
"status": "affected",
"version": "3.22.40"
},
{
"status": "affected",
"version": "3.22.41"
},
{
"status": "affected",
"version": "3.22.42"
},
{
"status": "affected",
"version": "3.22.43"
},
{
"status": "affected",
"version": "3.22.44"
},
{
"status": "affected",
"version": "3.22.45"
},
{
"status": "affected",
"version": "3.22.46"
},
{
"status": "affected",
"version": "3.22.47"
},
{
"status": "affected",
"version": "3.23.0"
},
{
"status": "affected",
"version": "3.23.1"
},
{
"status": "affected",
"version": "3.23.2"
},
{
"status": "affected",
"version": "3.23.3"
},
{
"status": "affected",
"version": "3.23.4"
},
{
"status": "affected",
"version": "3.23.5"
},
{
"status": "affected",
"version": "3.23.6"
},
{
"status": "affected",
"version": "3.23.7"
},
{
"status": "affected",
"version": "3.23.8"
},
{
"status": "affected",
"version": "3.23.9"
},
{
"status": "affected",
"version": "3.23.10"
},
{
"status": "affected",
"version": "3.23.11"
},
{
"status": "affected",
"version": "3.23.12"
},
{
"status": "affected",
"version": "3.23.13"
},
{
"status": "affected",
"version": "3.23.14"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "ZAST.AI (VulDB User)"
},
{
"lang": "en",
"type": "coordinator",
"value": "VulDB CNA Team"
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability was determined in Saleor up to 3.20.118/3.21.54/3.22.47/3.23.14. This vulnerability affects the function get_client_ip of the file saleor/account/throttling.py. Executing a manipulation can lead to improper restriction of excessive authentication attempts. The attack can be executed remotely. The attack requires a high level of complexity. It is stated that the exploitability is difficult. The exploit has been publicly disclosed and may be utilized. The projects own issue #19203 internal ticket admits \"IP can be spoofed in most deployments\" and that its REAL_IP_ENVIRON-type setting bypasses get_client_ip; fix (right-to-left RFC 7239 hop selection) proposed but still unmerged. The vendor explains within an email, that \"[t]his is not a vulnerability, this is working at intended, Saleor expects XFF to be configured properly\"."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 6.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 3.7,
"baseSeverity": "LOW",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 3.7,
"baseSeverity": "LOW",
"vectorString": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 2.6,
"vectorString": "AV:N/AC:H/Au:N/C:P/I:N/A:N/E:POC/RL:ND/RC:C",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-307",
"description": "Improper Restriction of Excessive Authentication Attempts",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-799",
"description": "Improper Control of Interaction Frequency",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-18T18:15:10.080Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-407477 | Saleor throttling.py get_client_ip excessive authentication",
"tags": [
"vdb-entry",
"technical-description"
],
"url": "https://vuldb.com/vuln/407477"
},
{
"name": "VDB-407477 | CTI Indicators (IOB, IOC, TTP, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/407477/cti"
},
{
"name": "CVE-2026-93650 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-93650"
},
{
"name": "Submit #933655 | saleor \u003c=3.23.14 Improper Restriction of Excessive Authentication Attempts",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/933655"
},
{
"tags": [
"exploit"
],
"url": "https://github.com/zast-ai/vulnerability-reports/blob/main/saleor/bruteforce.md"
},
{
"tags": [
"issue-tracking"
],
"url": "https://github.com/saleor/saleor/issues/19203"
},
{
"tags": [
"product"
],
"url": "https://github.com/saleor/saleor/"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-09-18T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-09-18T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-09-18T15:13:21.000Z",
"value": "VulDB entry last update"
}
],
"title": "Saleor throttling.py get_client_ip excessive authentication",
"x_generator": [
"VulDB PVTS v202609"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-93650",
"datePublished": "2026-09-18T18:15:10.080Z",
"dateReserved": "2026-09-18T13:07:36.010Z",
"dateUpdated": "2026-09-18T19:47:52.282Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-92583 (GCVE-0-2026-92583)
Vulnerability from cvelistv5 – Published: 2026-09-16 21:46 – Updated: 2026-09-17 14:49- CWE-307 - Improper Restriction of Excessive Authentication Attempts
| URL | Tags |
|---|---|
| https://github.com/WWBN/AVideo/security/advisorie… | vendor-advisory |
| https://www.vulncheck.com/advisories/avideo-throu… | third-party-advisory |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-92583",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-17T14:47:33.195595Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-17T14:49:33.344Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://github.com/WWBN/AVideo/security/advisories/GHSA-8jrm-qg5f-966w"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "AVideo",
"vendor": "WWBN",
"versions": [
{
"lessThanOrEqual": "29.0",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:wwbn:avideo:*:*:*:*:*:*:*:*",
"versionEndIncluding": "29.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "rajivraj"
}
],
"datePublic": "2026-09-01T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "AVideo through 29.0 contains a race condition in the enforceRateLimit() function that fails to atomically increment rate limit counters, allowing attackers to bypass all rate limits including login brute-force protection by issuing concurrent requests. Attackers can submit parallel credential attempts to exceed the documented 30-attempts-per-5-minutes login limit by an arbitrary factor determined only by their connection concurrency."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "LOW",
"vulnIntegrityImpact": "LOW"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-307",
"description": "Improper Restriction of Excessive Authentication Attempts",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-16T21:46:50.833Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Security Advisory (GHSA-8jrm-qg5f-966w)",
"tags": [
"vendor-advisory"
],
"url": "https://github.com/WWBN/AVideo/security/advisories/GHSA-8jrm-qg5f-966w"
},
{
"name": "VulnCheck Advisory: AVideo through 29.0 Rate Limit Bypass via Non-Atomic Counter Increment",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/avideo-through-29.0-rate-limit-bypass-via-non-atomic-counter-increment"
}
],
"title": "AVideo through 29.0 Rate Limit Bypass via Non-Atomic Counter Increment",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-92583",
"datePublished": "2026-09-16T21:46:50.833Z",
"dateReserved": "2026-09-16T13:47:20.117Z",
"dateUpdated": "2026-09-17T14:49:33.344Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-92082 (GCVE-0-2026-92082)
Vulnerability from cvelistv5 – Published: 2026-09-15 14:04 – Updated: 2026-09-15 14:58 X_Open Source- CWE-307 - Improper restriction of excessive authentication attempts
| URL | Tags |
|---|---|
| https://docs.azul.com/payara/release-notes/releas… | release-notes |
| https://docs.azul.com/payara/version/6/release-no… | release-notes |
| https://docs.azul.com/payara/version/5/release-no… | release-notes |
| https://docs.azul.com/payara/version/4/release-no… | release-notes |
| https://docs.azul.com/payara-community/release-no… | release-notes |
| Vendor | Product | Version | |
|---|---|---|---|
| Payara | Payara Server |
Affected:
7.0.0 , < 7.2.0
(semver)
Affected: 7.2025.1 , < 7.2026.7 (custom) Affected: 6.0.0 , < 6.40.0 (semver) Affected: 5.20.0 , < 5.89.0 (semver) Affected: 4.1.144 , < 4.1.2.191.57 (custom) Affected: 6.2023.1 (custom) Affected: 5.2020.1 (custom) |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-92082",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-15T14:58:27.927898Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-15T14:58:50.917Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "affected",
"modules": [
"Admin GUI"
],
"packageName": "org.glassfish.admingui.common.security",
"product": "Payara Server",
"programFiles": [
"org.glassfish.admingui.common.security.AdminConsoleAuthModule"
],
"repo": "https://github.com/payara/Payara/",
"vendor": "Payara",
"versions": [
{
"lessThan": "7.2.0",
"status": "affected",
"version": "7.0.0",
"versionType": "semver"
},
{
"lessThan": "7.2026.7",
"status": "affected",
"version": "7.2025.1",
"versionType": "custom"
},
{
"lessThan": "6.40.0",
"status": "affected",
"version": "6.0.0",
"versionType": "semver"
},
{
"lessThan": "5.89.0",
"status": "affected",
"version": "5.20.0",
"versionType": "semver"
},
{
"lessThan": "4.1.2.191.57",
"status": "affected",
"version": "4.1.144",
"versionType": "custom"
},
{
"status": "affected",
"version": "6.2023.1",
"versionType": "custom"
},
{
"status": "affected",
"version": "5.2020.1",
"versionType": "custom"
}
]
}
],
"datePublic": "2026-09-15T13:09:00.000Z",
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "By default, Payara Server does not limit the number of failed login attempts, which can leave it vulnerable to brute force login attacks. To mitigate this, Payara Server includes built-in automatic attack protection. For configuration details, see\u0026nbsp;\u003ca href=\"https://docs.azul.com/payara/technical-documentation/payara-server-documentation/security-guide/administering-system-security.html\" target=\"_blank\"\u003ehttps://docs.azul.com/payara/technical-documentation/payara-server-documentation/security-guide/administering-system-security.html\u003c/a\u003e."
}
],
"value": "By default, Payara Server does not limit the number of failed login attempts, which can leave it vulnerable to brute force login attacks. To mitigate this, Payara Server includes built-in automatic attack protection. For configuration details, see\u00a0 https://docs.azul.com/payara/technical-documentation/payara-server-documentation/security-guide/administering-system-security.html ."
}
],
"impacts": [
{
"capecId": "CAPEC-49",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-49 Password Brute Forcing"
}
]
},
{
"capecId": "CAPEC-16",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-16 Dictionary-based Password Attack"
}
]
},
{
"capecId": "CAPEC-565",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-565 Password Spraying"
}
]
},
{
"capecId": "CAPEC-600",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-600 Credential Stuffing"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "YES",
"Recovery": "USER",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "ADJACENT",
"baseScore": 6.3,
"baseSeverity": "MEDIUM",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "AMBER",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "HIGH",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "CONCENTRATED",
"vectorString": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N/AU:Y/R:U/V:C/RE:L/U:Amber",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "LOW",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "LOW"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-307",
"description": "CWE-307 Improper restriction of excessive authentication attempts",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-15T14:04:25.241Z",
"orgId": "769c9ae7-73c3-4e47-ae19-903170fc3eb8",
"shortName": "Payara"
},
"references": [
{
"tags": [
"release-notes"
],
"url": "https://docs.azul.com/payara/release-notes/release-notes-7.2.0.html"
},
{
"tags": [
"release-notes"
],
"url": "https://docs.azul.com/payara/version/6/release-notes/release-notes-6.40.0.html"
},
{
"tags": [
"release-notes"
],
"url": "https://docs.azul.com/payara/version/5/release-notes/release-notes-5.89.0.html"
},
{
"tags": [
"release-notes"
],
"url": "https://docs.azul.com/payara/version/4/release-notes/release-notes-4.1.2.191.57.html"
},
{
"tags": [
"release-notes"
],
"url": "https://docs.azul.com/payara-community/release-notes/release-notes-7.2026.7.html"
}
],
"source": {
"advisory": "CVE-2024-9342",
"discovery": "UPSTREAM"
},
"tags": [
"x_open-source"
],
"title": "Payara Server is vulnerable to brute-force login attacks due to the absence of a limit on failed login attempts",
"x_generator": {
"engine": "Vulnogram 1.0.5"
}
}
},
"cveMetadata": {
"assignerOrgId": "769c9ae7-73c3-4e47-ae19-903170fc3eb8",
"assignerShortName": "Payara",
"cveId": "CVE-2026-92082",
"datePublished": "2026-09-15T14:04:25.241Z",
"dateReserved": "2026-09-15T13:03:29.440Z",
"dateUpdated": "2026-09-15T14:58:50.917Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-91973 (GCVE-0-2026-91973)
Vulnerability from cvelistv5 – Published: 2026-09-15 15:18 – Updated: 2026-09-15 15:55- CWE-307 - Improper Restriction of Excessive Authentication Attempts
| URL | Tags |
|---|---|
| https://github.com/go-vikunja/vikunja/security/ad… | vendor-advisory |
| https://www.vulncheck.com/advisories/vikunja-befo… | third-party-advisory |
| Vendor | Product | Version | |
|---|---|---|---|
| go-vikunja | vikunja |
Affected:
0 , < 2.6.0
(semver)
Unaffected: 2.6.0 (semver) cpe:2.3:a:vikunja:vikunja:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-91973",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-15T15:53:33.159049Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-15T15:55:04.161Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://github.com/go-vikunja/vikunja/security/advisories/GHSA-m469-88xx-8rx2"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "vikunja",
"vendor": "go-vikunja",
"versions": [
{
"lessThan": "2.6.0",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "2.6.0",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:vikunja:vikunja:*:*:*:*:*:*:*:*",
"versionEndExcluding": "2.6.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "JellowBeanz26"
}
],
"datePublic": "2026-08-31T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Vikunja before 2.6.0 contains an authentication bypass vulnerability in CalDAV BasicAuth endpoints that lack rate limiting protection. Remote unauthenticated attackers can issue unbounded credential-guessing requests against /dav, /.well-known, and /feeds routes to bypass the instance\u0027s anti-brute-force controls and compromise password-only accounts."
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 8.7,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-307",
"description": "Improper Restriction of Excessive Authentication Attempts",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-15T15:18:23.488Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Security Advisory (GHSA-m469-88xx-8rx2)",
"tags": [
"vendor-advisory"
],
"url": "https://github.com/go-vikunja/vikunja/security/advisories/GHSA-m469-88xx-8rx2"
},
{
"name": "VulnCheck Advisory: Vikunja before 2.6.0 Authentication Bypass via CalDAV BasicAuth",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/vikunja-before-2.6.0-authentication-bypass-via-caldav-basicauth"
}
],
"title": "Vikunja before 2.6.0 Authentication Bypass via CalDAV BasicAuth",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-91973",
"datePublished": "2026-09-15T15:18:23.488Z",
"dateReserved": "2026-09-15T11:09:54.873Z",
"dateUpdated": "2026-09-15T15:55:04.161Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-91972 (GCVE-0-2026-91972)
Vulnerability from cvelistv5 – Published: 2026-09-15 15:18 – Updated: 2026-09-17 15:12- CWE-307 - Improper Restriction of Excessive Authentication Attempts
| URL | Tags |
|---|---|
| https://github.com/go-vikunja/vikunja/security/ad… | vendor-advisory |
| https://www.vulncheck.com/advisories/vikunja-befo… | third-party-advisory |
| Vendor | Product | Version | |
|---|---|---|---|
| go-vikunja | vikunja |
Affected:
0 , < 2.6.0
(semver)
Unaffected: 2.6.0 (semver) cpe:2.3:a:vikunja:vikunja:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-91972",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-17T15:11:53.582933Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-17T15:12:40.377Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://github.com/go-vikunja/vikunja/security/advisories/GHSA-6rvj-qwjf-3m4q"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "vikunja",
"vendor": "go-vikunja",
"versions": [
{
"lessThan": "2.6.0",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "2.6.0",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:vikunja:vikunja:*:*:*:*:*:*:*:*",
"versionEndExcluding": "2.6.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "JellowBeanz26"
}
],
"datePublic": "2026-08-31T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Vikunja versions before 2.6.0 fail to apply rate limiting to /api/v2 public authentication endpoints including login, register, password-reset, and OAuth token routes. Remote unauthenticated attackers can perform unbounded credential guessing, account enumeration, and password-reset flooding attacks without throttling restrictions."
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 8.7,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-307",
"description": "Improper Restriction of Excessive Authentication Attempts",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-15T15:18:22.792Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Security Advisory (GHSA-6rvj-qwjf-3m4q)",
"tags": [
"vendor-advisory"
],
"url": "https://github.com/go-vikunja/vikunja/security/advisories/GHSA-6rvj-qwjf-3m4q"
},
{
"name": "VulnCheck Advisory: Vikunja before 2.6.0 Authentication Bypass via Unthrottled API",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/vikunja-before-2.6.0-authentication-bypass-via-unthrottled-api"
}
],
"title": "Vikunja before 2.6.0 Authentication Bypass via Unthrottled API",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-91972",
"datePublished": "2026-09-15T15:18:22.792Z",
"dateReserved": "2026-09-15T11:09:54.873Z",
"dateUpdated": "2026-09-17T15:12:40.377Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-89174 (GCVE-0-2026-89174)
Vulnerability from cvelistv5 – Published: 2026-09-11 07:31 – Updated: 2026-09-11 15:49- CWE-307 - Improper Restriction of Excessive Authentication Attempts
| URL | Tags |
|---|---|
| https://www.twcert.org.tw/tw/cp-132-11198-b8bba-1.html | third-party-advisory |
| https://www.twcert.org.tw/en/cp-139-11199-38e1e-2.html | third-party-advisory |
| Vendor | Product | Version | |
|---|---|---|---|
| Kingdom Communication Associated | EH3040 |
Affected:
0 , < 2.5.0A
(custom)
|
|
| Kingdom Communication Associated | EH4200 |
Affected:
0 , < 2.5.0A
(custom)
|
|
| Kingdom Communication Associated | EH1000B |
Affected:
0 , < 2.7.0A
(custom)
|
|
| Kingdom Communication Associated | EH2070 |
Affected:
0 , < 2.8.0A
(custom)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-89174",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-11T15:47:22.171888Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-11T15:49:30.661Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "EH3040",
"vendor": "Kingdom Communication Associated",
"versions": [
{
"lessThan": "2.5.0A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "EH4200",
"vendor": "Kingdom Communication Associated",
"versions": [
{
"lessThan": "2.5.0A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "EH1000B",
"vendor": "Kingdom Communication Associated",
"versions": [
{
"lessThan": "2.7.0A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "EH2070",
"vendor": "Kingdom Communication Associated",
"versions": [
{
"lessThan": "2.8.0A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"datePublic": "2026-09-11T07:28:00.000Z",
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eSmart Video Intercom System developed by Kingdom Communication Associated has a Missing Brute-force Protection vulnerability. Unauthenticated remote attackers can gain access to valid accounts through a large number of login attempts.\u003c/p\u003e"
}
],
"value": "Smart Video Intercom System developed by Kingdom Communication Associated has a Missing Brute-force Protection vulnerability. Unauthenticated remote attackers can gain access to valid accounts through a large number of login attempts."
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 8.7,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-307",
"description": "CWE-307 Improper Restriction of Excessive Authentication Attempts",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-11T07:31:15.921Z",
"orgId": "cded6c7f-6ce5-4948-8f87-aa7a3bbb6b0e",
"shortName": "twcert"
},
"references": [
{
"tags": [
"third-party-advisory"
],
"url": "https://www.twcert.org.tw/tw/cp-132-11198-b8bba-1.html"
},
{
"tags": [
"third-party-advisory"
],
"url": "https://www.twcert.org.tw/en/cp-139-11199-38e1e-2.html"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eUpdate EH3040 to version 2.5.0A\u003cbr\u003eUpdate EH4200 to version 2.5.0A\u003cbr\u003eUpdate EH1000B to version 2.7.0A\u003cbr\u003eUpdate EH2070 to version 2.8.0A\u003c/p\u003e"
}
],
"value": "Update EH3040 to version 2.5.0A\nUpdate EH4200 to version 2.5.0A\nUpdate EH1000B to version 2.7.0A\nUpdate EH2070 to version 2.8.0A"
}
],
"source": {
"advisory": "TVN-202609004",
"discovery": "EXTERNAL"
},
"title": "Kingdom Communication Associated\uff5cSmart Video Intercom System - Missing Burte-force Protection",
"x_generator": {
"engine": "Vulnogram 1.0.5"
}
}
},
"cveMetadata": {
"assignerOrgId": "cded6c7f-6ce5-4948-8f87-aa7a3bbb6b0e",
"assignerShortName": "twcert",
"cveId": "CVE-2026-89174",
"datePublished": "2026-09-11T07:31:15.921Z",
"dateReserved": "2026-09-11T06:14:46.734Z",
"dateUpdated": "2026-09-11T15:49:30.661Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
Mitigation
- Common protection mechanisms include:
- Disconnecting the user after a small number of failed attempts
- Implementing a timeout
- Locking out a targeted account
- Requiring a computational task on the user's part.
Mitigation MIT-4
Strategy: Libraries or Frameworks
- Use a vetted library or framework that does not allow this weakness to occur or provides constructs that make this weakness easier to avoid [REF-1482].
- Consider using libraries with authentication capabilities such as OpenSSL or the ESAPI Authenticator. [REF-45]
CAPEC-16: Dictionary-based Password Attack
An attacker tries each of the words in a dictionary as passwords to gain access to the system via some user's account. If the password chosen by the user was a word within the dictionary, this attack will be successful (in the absence of other mitigations). This is a specific instance of the password brute forcing attack pattern.
Dictionary Attacks differ from similar attacks such as Password Spraying (CAPEC-565) and Credential Stuffing (CAPEC-600), since they leverage unknown username/password combinations and don't care about inducing account lockouts.
CAPEC-49: Password Brute Forcing
An adversary tries every possible value for a password until they succeed. A brute force attack, if feasible computationally, will always be successful because it will essentially go through all possible passwords given the alphabet used (lower case letters, upper case letters, numbers, symbols, etc.) and the maximum length of the password.
CAPEC-560: Use of Known Domain Credentials
An adversary guesses or obtains (i.e. steals or purchases) legitimate credentials (e.g. userID/password) to achieve authentication and to perform authorized actions under the guise of an authenticated user or service.
CAPEC-565: Password Spraying
In a Password Spraying attack, an adversary tries a small list (e.g. 3-5) of common or expected passwords, often matching the target's complexity policy, against a known list of user accounts to gain valid credentials. The adversary tries a particular password for each user account, before moving onto the next password in the list. This approach assists the adversary in remaining undetected by avoiding rapid or frequent account lockouts. The adversary may then reattempt the process with additional passwords, once enough time has passed to prevent inducing a lockout.
CAPEC-600: Credential Stuffing
An adversary tries known username/password combinations against different systems, applications, or services to gain additional authenticated access. Credential Stuffing attacks rely upon the fact that many users leverage the same username/password combination for multiple systems, applications, and services.
CAPEC-652: Use of Known Kerberos Credentials
An adversary obtains (i.e. steals or purchases) legitimate Kerberos credentials (e.g. Kerberos service account userID/password or Kerberos Tickets) with the goal of achieving authenticated access to additional systems, applications, or services within the domain.
CAPEC-653: Use of Known Operating System Credentials
An adversary guesses or obtains (i.e. steals or purchases) legitimate operating system credentials (e.g. userID/password) to achieve authentication and to perform authorized actions on the system, under the guise of an authenticated user or service. This applies to any Operating System.