← Back to search

CVE-2026-71213

9.1 CRITICALpublic exploit available

Published 2026-08-05 · Updated 2026-08-10

AI risk analysis

Summary
The flaw allows an attacker to perform unlimited password-guessing attempts against any account, including administrators, due to the absence of rate-limiting or account lockout mechanisms when the captcha is disabled, which is the default configuration.
Exploitability
Exploitation is relatively easy as the default configuration disables the captcha, allowing an attacker to send unlimited requests without any throttling or account lockout.
Blast radius
If exploited, this flaw could lead to unauthorized access to sensitive accounts, potentially compromising the entire system, including administrative accounts.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Enable the captcha feature, or implement rate-limiting and account lockout mechanisms for the login endpoint.
auth-bypassrate-limitingweb

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

Typemill's login endpoint (POST /tm/login, ControllerWebAuth::login) performs no rate-limiting, failed-attempt counting, or account lockout when captcha is disabled, which is the default configuration. An unauthenticated attacker can send unlimited password-guessing requests against any account, including administrators, with no throttling.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Weaknesses

CWE-307

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.