CVE-2025-13986

Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Disable Login Page allows Functionality Bypass.This issue affects Disable Login Page: from 0.0.0 before 1.1.3.
References
Link Resource
https://www.drupal.org/sa-contrib-2025-124 Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:zyxware:disable_login_page:*:*:*:*:*:drupal:*:*

History

06 Feb 2026, 19:00

Type Values Removed Values Added
First Time Zyxware
Zyxware disable Login Page
References () https://www.drupal.org/sa-contrib-2025-124 - () https://www.drupal.org/sa-contrib-2025-124 - Third Party Advisory
CPE cpe:2.3:a:zyxware:disable_login_page:*:*:*:*:*:drupal:*:*

02 Feb 2026, 18:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 4.8
v2 : unknown
v3 : 4.2

02 Feb 2026, 15:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 7.5
v2 : unknown
v3 : 4.8

29 Jan 2026, 19:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

28 Jan 2026, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-28 20:16

Updated : 2026-02-06 19:00


NVD link : CVE-2025-13986

Mitre link : CVE-2025-13986

CVE.ORG link : CVE-2025-13986


JSON object : View

Products Affected

zyxware

  • disable_login_page
CWE
CWE-288

Authentication Bypass Using an Alternate Path or Channel