CVE-2026-6223: OTP Bypass in Bahçelievler Muncipality's BiHayat App
Published Sep 7, 2026
·Updated
Improper restriction of excessive authentication attempts vulnerability in Bahçelievler Muncipality BiHayat App allows Authentication Bypass.
This issue affects BiHayat App: from 2.1.7 through 07092026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
1 affected component
BiHayat App>=2.1.7<=07092026
Event History
Sep 7, 2026
CVE Published
via MITRE·12:30 PM
Data Sourced
via MITRE·12:30 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What does an attacker need to exploit this issue?
The vulnerability is remotely exploitable with low attack complexity, requires no privileges, and does not require user interaction. It stems from insufficient restriction of excessive authentication attempts, enabling authentication bypass.
2
Which versions are affected?
BiHayat App versions from 2.1.7 through 07092026 are listed as affected.
3
Is a vendor fix available?
The available information does not identify a fix. The vendor was contacted early about the disclosure but did not respond.