Disable Login Page - Moderately critical - Access bypass - SA-CONTRIB-2026-111
Project: Disable Login PageDate: 2026-August-26Security risk: Moderately critical 13 ∕ 25 AC:None/A:None/CI:None/II:None/E:Proof/TD:AllVulnerability: Access bypassAffected versions: <= 1.1.4CVE IDs: CVE-2026-81269Description: This module enables you to disable access to the /user/login form unless a secret key is provided.
The module does not invalidate the relevant caches when login page access restrictions are enabled. As a result, previously cached login page responses may remain accessible until caches are cleared. An attacker may continue to access the login page despite the restriction having been enabled.Solution: Install the latest version:
- If you use the Disable Login Page module, upgrade to Disable Login Page 1.1.4.
Reported By:
Fixed By:
Coordinated By:
- Greg Knaddison (greggles) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team
- Pierre Rudloff (prudloff) of the Drupal Security Team
- Jess (xjm) of the Drupal Security Team

