PatchSiren cyber security CVE debrief
CVE-2026-16647 Drupal CVE debrief
The Disable Login Page module for Drupal is vulnerable to an Authentication Bypass Using an Alternate Path or Channel attack, affecting versions from 0.0.0 to 1.1.4. This issue allows attackers to bypass authentication mechanisms, potentially leading to unauthorized access. Drupal users who have installed the Disable Login Page module, especially those using versions prior to 1.1.5, should be aware of this vulnerability and take necessary actions to mitigate the risk. The CVE record was published on 2026-09-02T13:17:07.243Z and has not been modified since then. The CVSS score is 4.1, with a severity of MEDIUM.
- Vendor
- Drupal
- Product
- Disable Login Page
- CVSS
- MEDIUM 4.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-02
- Original CVE updated
- 2026-09-04
- Advisory published
- 2026-09-02
- Advisory updated
- 2026-09-04
Who should care
Drupal users who have installed the Disable Login Page module, especially those using versions prior to 1.1.5, should be aware of this vulnerability and take necessary actions to mitigate the risk. This includes administrators, security teams, and operators responsible for maintaining Drupal installations with the Disable Login Page module enabled.
Technical summary
The Disable Login Page module for Drupal is vulnerable to an Authentication Bypass Using an Alternate Path or Channel attack. This issue affects versions from 0.0.0 to 1.1.4 of the module. A CVSS score of 4.1 and a severity of MEDIUM have been assigned. The vulnerability allows attackers to bypass authentication mechanisms, potentially leading to unauthorized access. Users should prioritize patching the Disable Login Page module to prevent potential authentication bypass attacks.
Defensive priority
Drupal users should prioritize patching the Disable Login Page module to prevent potential authentication bypass attacks.
Recommended defensive actions
- Apply patches or updates for Disable Login Page module versions prior to 1.1.5
- Restrict access to the Disable Login Page module configuration
- Monitor for suspicious activity related to authentication bypass attempts
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE-2026-16647 record indicates an Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Disable Login Page module versions from 0.0.0 to 1.1.4. The CVSS score is 4.1, with a severity of MEDIUM. Evidence is limited to CVE and NVD details. Defenders should verify affected deployments, review official advisories, and monitor for suspicious activity related to authentication bypass attempts.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-16647 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-16647
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-16647 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-16647
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://www.drupal.org/sa-contrib-2026-111
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.