CVE-2025-13986: Disable Login Page - Critical - Access bypass - SA-CONTRIB-2025-124
Published Jan 28, 2026
·Updated
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Disable Login Page allows Functionality Bypass.This issue affects Disable Login Page: from 0.0.0 before 1.1.3.
Affected Software
2 affected components
drupal/disable_login_page<1.1.3
Zyxware Disable Login Page Drupal<1.1.3
Event History
Jan 28, 2026
CVE Published
via MITRE·08:02 PM
Data Sourced
via MITRE·08:02 PM
DescriptionWeakness
Data Sourced
via NVD·08:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-13986?
CVE-2025-13986 is classified as a critical vulnerability due to its ability to enable access bypass.
2
How do I fix CVE-2025-13986?
To fix CVE-2025-13986, update the Disable Login Page module to version 1.1.3 or later.
3
Which versions of Disable Login Page are affected by CVE-2025-13986?
CVE-2025-13986 affects versions of Disable Login Page prior to 1.1.3.
4
What kind of vulnerability is CVE-2025-13986?
CVE-2025-13986 is an Authentication Bypass vulnerability using an alternate path or channel.
5
What impact does CVE-2025-13986 have on my Drupal site?
The impact of CVE-2025-13986 allows unauthorized users to access restricted functionalities on your Drupal site.