Brute Force Attack Protection Vulnerability in Drupal by Acquia
CVE-2026-11915

5.9MEDIUM

Key Information:

Vendor

Drupal

Vendor
CVE Published:
10 July 2026

What is CVE-2026-11915?

A vulnerability has been identified in the brute force attack protection mechanism within Drupal, putting user accounts at risk of unauthorized access. This issue arises from insufficient protection against brute force attempts, which could potentially allow attackers to exploit weak passwords. It is crucial for users of the affected version to apply available updates to mitigate the risk and enhance their security posture.

Affected Version(s)

Brute force attack protection *.*

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.