Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-100501— Flame through 2.4.0 Brute-Force Attack via Login Endpoint

Quick assessment

Affected
pawelmalak flame
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Flame 2.4.0 及更早版本在 POST /api/auth 登录接口中存在一种“对过多认证尝试限制不当”的安全漏洞。该漏洞允许未认证的攻击者对管理员密码执行暴力破解。攻击者可以无限制地提交密码猜测请求,系统未实施速率限制、尝试次数计数、账户锁定或延迟等防护机制,从而导致攻击者能够获取完整的管理员权限,并修改应用程序配置。

CVSS 6.5 · Medium EPSS 0.29% · P20
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-100501

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Flame through 2.4.0 Brute-Force Attack via Login Endpoint
Source: CVE Program / CVE List V5
Vulnerability Description
Flame through 2.4.0 contains an improper restriction of excessive authentication attempts vulnerability in the POST /api/auth login endpoint that allows unauthenticated attackers to brute-force the admin password. Attackers can submit unlimited password guesses without rate limiting, attempt counters, lockouts, or delays to gain full administrator access and modify application configuration.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
过多认证尝试的限制不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
pawelmalak flame 0 ~ 2.4.0 -

II. Public POCs for CVE-2026-100501

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-100501

请登录查看更多情报信息。

Other References for CVE-2026-100501 (1)

Other References for CVE-2026-100501 (5)

Same Patch Batch · pawelmalak · 2026-09-25 · 3 CVEs total

CVE-2026-100418 5.3 MEDIUM Flame through 2.4.0 Information Exposure via GET /api/config
CVE-2026-100502 5.0 MEDIUM Flame through 2.4.0 Admin Token Insufficient Session Expiration

IV. Related Vulnerabilities

V. Comments for CVE-2026-100501

No comments yet


Leave a comment