PatchSiren cyber security CVE debrief
CVE-2026-18260 Drupal CVE debrief
The CVE-2026-18260 vulnerability is an Improper Restriction of Excessive Authentication Attempts issue in the Drupal Disable Login Page module. This vulnerability allows for brute-force attacks and affects versions from 0.0.0 to 1.1.4. The CVSS score is 5.7, indicating a MEDIUM severity. Affected Drupal users should review their installations and apply patches or mitigations as necessary. The Disable Login Page module's vulnerability could lead to unauthorized access if exploited. Users should verify their module versions and update to 1.1.4 or later. Additionally, users can restrict login attempts and monitor for suspicious activity to help prevent brute-force attacks.
- Vendor
- Drupal
- Product
- Disable Login Page
- CVSS
- MEDIUM 5.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-25
- Original CVE updated
- 2026-09-02
- Advisory published
- 2026-08-25
- Advisory updated
- 2026-09-02
Who should care
Drupal users who have installed the Disable Login Page module should be aware of this vulnerability and take steps to patch their installations. This includes reviewing their module versions, applying patches or mitigations, and monitoring for suspicious activity. Additionally, security teams and vulnerability management teams should review the vulnerability's impact and prioritize patching the Disable Login Page module to prevent potential brute-force attacks.
Technical summary
The CVE-2026-18260 vulnerability is an Improper Restriction of Excessive Authentication Attempts issue in the Drupal Disable Login Page module. This vulnerability allows for brute-force attacks and affects versions from 0.0.0 to 1.1.4. The CVSS score is 5.7, indicating a MEDIUM severity. The vulnerability is caused by inadequate restrictions on authentication attempts, which could allow attackers to use brute-force methods to gain unauthorized access.
Defensive priority
Drupal users should prioritize patching the Disable Login Page module to prevent potential brute-force attacks.
Recommended defensive actions
- Apply patches for Disable Login Page module version 1.1.4 or later
- Restrict login attempts to prevent brute-force attacks
- Monitor for suspicious login activity
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The CVE-2026-18260 record indicates an Improper Restriction of Excessive Authentication Attempts vulnerability in the Drupal Disable Login Page module. The issue affects versions from 0.0.0 to 1.1.4. The CVSS score is 5.7, with a severity of MEDIUM. Evidence is based on the official CVE Program record and NIST NVD detail page. The vulnerability's impact is limited to the Disable Login Page module, and there are no known instances of exploitation. However, defenders should verify affected scope and apply patches or mitigations.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-18260 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-18260
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-18260 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-18260
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://www.drupal.org/sa-contrib-2026-110
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.