CVE-2026-27546: Authentication Bypass in _account_log
Published Sep 16, 2026
·Updated
An unauthenticated remote attacker can exploit an authentication bypass in the accountlog function to log in as an admin, even when accounts are properly configured.
Event History
Sep 16, 2026
CVE Published
via MITRE·07:48 AM
Data Sourced
via MITRE·07:48 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An unauthenticated remote attacker can exploit it. No prior account access or user interaction is required.
2
Are correctly configured accounts protected?
No. The issue can allow an attacker to log in as an administrator even when accounts are properly configured.
3
What level of access could an attacker obtain?
Successful exploitation can provide administrative login access. The supplied severity vector indicates high potential impact to confidentiality, integrity, and availability.