Improper Authentication Management in Flame through 2.4.0 by Pawel Malak
CVE-2026-100501

8.3HIGH

Key Information:

Vendor

Pawelmalak

Status
Vendor
CVE Published:
25 September 2026

What is CVE-2026-100501?

Flame through version 2.4.0 features a significant vulnerability within the POST /api/auth login endpoint, where an improper restriction of authentication attempts allows unauthorized access. Attackers can exploit this flaw to perform a brute-force attack, sending an unlimited number of password guesses without facing any rate limiting, counters, or lockouts. This exposes the application to a critical risk, as it enables attackers to gain full administrative access and modify essential configurations, potentially leading to severe operational and security issues.

Affected Version(s)

flame 0 <= 2.4.0

References

CVSS V4

Score:
8.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Whispergate Security Research
.