CVE-2026-14254: Improper Restriction of Excessive Authentication Attempts in Delphix Continuous Data
A race condition in the account lockout mechanism in Delphix Continous Data allowed the lockout threshold to be bypassed through concurrent authentication requests. Parallel login attempts were processed before the failed-login counter and lockout status were updated, defeating brute-force protections and enabling continued password guessing against a targeted account.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Delphix Continuous Datato a version that resolves this vulnerability.Fixed in 2026.4.0.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-14254?
The severity of CVE-2026-14254 is high with a CVSS score of 8.3.
How do I fix CVE-2026-14254?
To fix CVE-2026-14254, apply the latest security updates provided by Delphix for Delphix Continuous Data.
What is the risk associated with CVE-2026-14254?
CVE-2026-14254 poses a risk score of 60, indicating a significant threat to security due to improper account lockout mechanisms.
What is the nature of the vulnerability in CVE-2026-14254?
CVE-2026-14254 is caused by a race condition that allows the bypass of account lockout thresholds in Delphix Continuous Data.
Which software is affected by CVE-2026-14254?
CVE-2026-14254 affects Delphix Continuous Data.