Authentication Bypass Vulnerability in Drupal Disable Login Page
CVE-2026-16647

Currently unrated

Key Information:

Vendor

Drupal

Vendor
CVE Published:
2 September 2026

What is CVE-2026-16647?

An issue has been identified in the Disable Login Page module for Drupal that allows an authentication bypass through an alternate path or channel. This vulnerability may permit unauthorized users to gain access to restricted functionalities, thereby compromising the integrity of user authentication mechanisms. Specifically, it affects versions from 0.0.0 up to 1.1.4, highlighting the urgency for users to update and secure their installations to prevent potential exploitation.

Affected Version(s)

Disable Login Page 0.0.0 < 1.1.4

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Brian Osborne (bkosborne)
Jason Partyka (partyka)
Brian Osborne (bkosborne)
Jason Partyka (partyka)
Greg Knaddison (greggles)
Juraj Nemec (poker10)
Pierre Rudloff (prudloff)
Jess (xjm)
.