Disable Login Page - Moderately critical - Access bypass - SA-CONTRIB-2026-110
Project: Disable Login PageDate: 2026-August-26Security risk: Moderately critical 13 ∕ 25 AC:Basic/A:None/CI:Some/II:None/E:Theoretical/TD:AllVulnerability: Access bypassAffected versions: <= 1.1.4CVE IDs: CVE-2026-18260Description: This module enables you to disable access to the /user/login form unless a secret key is provided.
The module does not sufficiently restrict repeated attempts to guess that key, allowing brute-force attacks against the access-control mechanism.Solution: Install the latest version:
- If you use the Disable Login Page module, upgrade to Disable Login Page 1.1.4.
Reported By:
- Pierre Rudloff (prudloff) of the Drupal Security Team
Fixed By:
Coordinated By:
- Neil Drumm (drumm) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Dave Long (longwave) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team
- Pierre Rudloff (prudloff) of the Drupal Security Team
- Jess (xjm) of the Drupal Security Team

