Drupal BruteForceProtection Vulnerability (CVE-2026-11915)
CVE-2026-11915 Published on July 10, 2026

Brute force attack protection - Critical - Unsupported - SA-CONTRIB-2026-047
vulnerability in Drupal Brute force attack protection allows . This issue affects Brute force attack protection versions: *.*.

NVD

Vulnerability Analysis

CVE-2026-11915 can be exploited with network access, and requires user privileges. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality and integrity, and no impact on availability.

Attack Vector:
NETWORK
Attack Complexity:
HIGH
Privileges Required:
HIGH
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
NONE

Weakness Type

Improper Restriction of Excessive Authentication Attempts

The software does not implement sufficient measures to prevent multiple failed authentication attempts within in a short time frame, making it more susceptible to brute force attacks.


Affected Versions

Drupal Brute force attack protection Version *.* is affected by CVE-2026-11915