Overview
A notable security flaw has been identified in the ‘Login Disable’ module for Drupal, designated as CVE-2026-1917. This vulnerability is an ‘Authentication Bypass,’ meaning it could allow unauthorized individuals to circumvent login restrictions, potentially gaining access to areas they shouldn’t. This type of vulnerability typically exploits an alternate path or channel to bypass normal authentication procedures, undermining the intended security controls of the module.
CVE Details
This particular issue affects the Login Disable module, which is a component used within Drupal websites. It was officially made public on March 25, 2026, and has since been thoroughly analyzed by security experts. The severity level for this vulnerability is rated as Medium.
- Product: Login Disable (Drupal module)
- Published Date: March 25, 2026
- Severity: Medium
- Status: Analyzed
Affected Products
The vulnerability specifically impacts the Drupal ‘Login Disable’ module. If you are using any version of this module from 0.0.0 up to, but not including, version 2.1.3, your system could be at risk. This means versions 2.1.2 and earlier are vulnerable, while version 2.1.3 and later are considered secure. It is crucial for administrators to verify their module versions to determine if they are impacted.
Current Status
As of its last modification on April 2, 2026, this vulnerability has been fully analyzed. This indicates that security researchers have thoroughly investigated the flaw, understood its nature, and confirmed its existence and potential impact. The analysis provides a clear picture for developers and administrators on how to address the issue.
Severity Level
With a CVSS score of 4.3, this issue is categorized as ‘Medium’ severity. An authentication bypass vulnerability at this level typically means that an attacker might be able to get past certain login protections without needing proper credentials. While not the most critical, it still poses a significant risk as it could lead to unauthorized access and potential misuse of website functionalities that are meant to be restricted, depending on the role and permissions an attacker might gain.
Possible Solutions
The primary and most effective solution to mitigate this vulnerability is to update your ‘Login Disable’ module for Drupal. Ensure you upgrade to version 2.1.3 or a later release as soon as possible. These updated versions contain the necessary patches to close the authentication bypass loophole. Regularly checking for and applying updates for all your Drupal modules and core is a crucial security practice. We recommend consulting the official Drupal security advisories for the most detailed patching instructions; however, specific details for this CVE are not immediately accessible via the provided public reference at this time.
References
- https://www.drupal.org/sa-contrib-2026-008


