Protection mechanism failure in HFS - CVE-2026-61503
Published: October 6, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass anti-brute-force login protections.
The vulnerability exists due to failure to invoke the failed-login event in the login API when handling an invalid username. A remote attacker can repeatedly submit login initiation requests with invalid usernames to bypass anti-brute-force login protections.
The issue affects plugin handling of failed login attempts for invalid usernames.