Improper Restriction of Excessive Authentication Attempts in baserCMS - #VU152765
Published: September 29, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass two-factor authentication and gain administrator access.
The vulnerability exists due to improper restriction of excessive authentication attempts in the admin 2FA verification endpoints and TwoFactorAuthenticationsService::verify() when submitting repeated 2FA verification codes. A remote attacker can submit unlimited six-digit code guesses to bypass two-factor authentication and gain administrator access.
Two-factor authentication must be enabled, and exploitation requires knowledge of a valid administrator password within the code validity window.