CVE-2026-13348: Security vulnerability
Published Sep 1, 2026
·Updated
CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could allow an attacker to gain unauthorized access to a user account by performing an arbitrary number of authentication attempts when redirect handling is disabled.
Event History
Sep 1, 2026
CVE Published
via MITRE·01:31 PM
Data Sourced
via MITRE·01:31 PM
DescriptionWeakness
Frequently Asked Questions
1
What configuration is required for this issue to be exploitable?
The vulnerability is exposed when redirect handling is disabled. The provided information does not establish whether this is the default configuration.
2
What does an attacker need to do to exploit the issue?
An attacker can perform an arbitrary number of authentication attempts against a user account, enabling repeated attempts to gain unauthorized access.