Improper Authentication Management in Flame through 2.4.0 by Pawel Malak
CVE-2026-100501
8.3HIGH
What is CVE-2026-100501?
Flame through version 2.4.0 features a significant vulnerability within the POST /api/auth login endpoint, where an improper restriction of authentication attempts allows unauthorized access. Attackers can exploit this flaw to perform a brute-force attack, sending an unlimited number of password guesses without facing any rate limiting, counters, or lockouts. This exposes the application to a critical risk, as it enables attackers to gain full administrative access and modify essential configurations, potentially leading to severe operational and security issues.
Affected Version(s)
flame 0 <= 2.4.0
