Drupal BruteForceProtection Vulnerability (CVE-2026-11915)
CVE-2026-11915 Published on July 10, 2026
Brute force attack protection - Critical - Unsupported - SA-CONTRIB-2026-047
vulnerability in Drupal Brute force attack protection allows . This issue affects Brute force attack protection versions: *.*.
Vulnerability Analysis
CVE-2026-11915 can be exploited with network access, and requires user privileges. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality and integrity, and no impact on availability.
Weakness Type
Improper Restriction of Excessive Authentication Attempts
The software does not implement sufficient measures to prevent multiple failed authentication attempts within in a short time frame, making it more susceptible to brute force attacks.