Drupal Disable Login Page Authentication Bypass (0.0.01.1.4) via Alternate Path
CVE-2026-16647 Published on September 2, 2026
Disable Login Page - Moderately critical - Access bypass - SA-CONTRIB-2026-111
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Disable Login Page allows Functionality Bypass. This issue affects Disable Login Page versions: from 0.0.0 to 1.1.4.
Vulnerability Analysis
CVE-2026-16647 can be exploited with network access, and requires user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a small impact on confidentiality, a small impact on integrity and availability.
Weakness Type
Authentication Bypass Using an Alternate Path or Channel
A product requires authentication, but the product has an alternate path or channel that does not require authentication.
Affected Versions
Drupal Disable Login Page:- Version 0.0.0 and below 1.1.4 is affected.