PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-16647 Drupal CVE debrief

The Disable Login Page module for Drupal is vulnerable to an Authentication Bypass Using an Alternate Path or Channel attack, affecting versions from 0.0.0 to 1.1.4. This issue allows attackers to bypass authentication mechanisms, potentially leading to unauthorized access. Drupal users who have installed the Disable Login Page module, especially those using versions prior to 1.1.5, should be aware of this vulnerability and take necessary actions to mitigate the risk. The CVE record was published on 2026-09-02T13:17:07.243Z and has not been modified since then. The CVSS score is 4.1, with a severity of MEDIUM.

Vendor
Drupal
Product
Disable Login Page
CVSS
MEDIUM 4.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-02
Original CVE updated
2026-09-04
Advisory published
2026-09-02
Advisory updated
2026-09-04

Who should care

Drupal users who have installed the Disable Login Page module, especially those using versions prior to 1.1.5, should be aware of this vulnerability and take necessary actions to mitigate the risk. This includes administrators, security teams, and operators responsible for maintaining Drupal installations with the Disable Login Page module enabled.

Technical summary

The Disable Login Page module for Drupal is vulnerable to an Authentication Bypass Using an Alternate Path or Channel attack. This issue affects versions from 0.0.0 to 1.1.4 of the module. A CVSS score of 4.1 and a severity of MEDIUM have been assigned. The vulnerability allows attackers to bypass authentication mechanisms, potentially leading to unauthorized access. Users should prioritize patching the Disable Login Page module to prevent potential authentication bypass attacks.

Defensive priority

Drupal users should prioritize patching the Disable Login Page module to prevent potential authentication bypass attacks.

Recommended defensive actions

  • Apply patches or updates for Disable Login Page module versions prior to 1.1.5
  • Restrict access to the Disable Login Page module configuration
  • Monitor for suspicious activity related to authentication bypass attempts
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE-2026-16647 record indicates an Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Disable Login Page module versions from 0.0.0 to 1.1.4. The CVSS score is 4.1, with a severity of MEDIUM. Evidence is limited to CVE and NVD details. Defenders should verify affected deployments, review official advisories, and monitor for suspicious activity related to authentication bypass attempts.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-16647 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-16647

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-16647 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-16647

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.