CVE-2026-102248: Rebuild Login Endpoint login improper authentication
A vulnerability was identified in Rebuild up to 4.4.7/4.5.0-beta5. This affects an unknown part of the file /user/login of the component Login Endpoint. The manipulation leads to improper authentication. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
Which deployments should be treated as potentially affected?
Rebuild installations using the Login Endpoint are potentially affected if they run a version up to 4.4.7 or 4.5.0-beta5. The affected functionality is associated with /user/login.
Can this be exploited remotely without prior access?
Yes. The issue can be initiated remotely, and the vector indicates no privileges or user interaction are required.
Is public exploit material available?
Yes. The available information states that a public exploit exists and may be used.
Is a vendor fix or response confirmed?
No vendor response is reported. The vendor was contacted early about the disclosure but did not respond.