CVE-2026-16647: Disable Login Page - Moderately critical - Access bypass - SA-CONTRIB-2026-111
Published Sep 2, 2026
·Updated
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Disable Login Page allows Functionality Bypass. This issue affects Disable Login Page versions: from 0.0.0 to 1.1.4.
Affected Software
1 affected component
Disable Login Page>=0.0.0<=1.1.4
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
drupal/disable_login_pageto a version that resolves this vulnerability.Fixed in 1.1.4Patch SA-CONTRIB-2026-111
Event History
Sep 2, 2026
CVE Published
via MITRE·12:55 PM
Data Sourced
via MITRE·12:55 PM
DescriptionWeakness
Frequently Asked Questions
1
Which installations are affected?
Disable Login Page versions from 0.0.0 through 1.1.4 are affected.
2
What is the impact of successful exploitation?
The vulnerability allows an authentication bypass through an alternate path or channel, resulting in functionality bypass.