CVE-2025-10928: Access code - Moderately critical - Access bypass - SA-CONTRIB-2025-108
Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Access code allows Brute Force. This issue affects Access code: from 0.0.0 before 2.0.5.
Other sources
Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Access code allows Brute Force.This issue affects Access code: from 0.0.0 before 2.0.5.
— MITRE
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2025-10928?
CVE-2025-10928 has been classified as a critical severity vulnerability due to its potential to allow brute force attacks.
How do I fix CVE-2025-10928?
To fix CVE-2025-10928, update Drupal Access code to version 2.0.5 or later.
Which versions of Drupal Access code are affected by CVE-2025-10928?
CVE-2025-10928 affects Drupal Access code versions from 0.0.0 up to, but not including, 2.0.5.
What type of vulnerability is CVE-2025-10928?
CVE-2025-10928 is classified as an Improper Restriction of Excessive Authentication Attempts vulnerability.
Can CVE-2025-10928 lead to unauthorized access?
Yes, CVE-2025-10928 can lead to unauthorized access through successful brute force attacks.