DRUPAL-CONTRIB-2026-008

See a problem?
Import Source
https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/login_disable/DRUPAL-CONTRIB-2026-008.json
JSON Data
https://api.osv.dev/v1/vulns/DRUPAL-CONTRIB-2026-008
Aliases
Published
2026-02-04T17:23:40Z
Modified
2026-09-10T03:46:00Z
Summary
[none]
Details

The Login Disable module prevents users from logging in to your Drupal site unless they know the access key to add to the end of the login form page.
( default: http://example.com/user/login?admin )
If they provide the access key and have a specific role they can log in.

The module does not check for the access key when using the HTTP request login route. It is possible to use this route to log in without providing the access key.

References
Credits

Affected packages

Packagist:https://packages.drupal.org/8 / drupal/login_disable

Package

Name
drupal/login_disable
Purl
pkg:composer/drupal/login_disable?repository_url=https:%2F%2Fpackages.drupal.org%2F8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.1.3
Database specific
Show details
{
    "constraint": "<2.1.3"
}

Database specific

affected_versions
"<2.1.3"
source
"https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/login_disable/DRUPAL-CONTRIB-2026-008.json"