Description
A vulnerability was identified in Rebuild up to 4.4.7/4.5.0-beta5. This affects an unknown part of the file /user/login of the component Login Endpoint. The manipulation leads to improper authentication. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-09-29
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Improper Authentication potentially leading to unauthorized access
Action: Upgrade
AI Analysis

Impact

The vulnerability is an improper authentication flaw in the Rebuild Login Endpoint. An attacker can manipulate the login process to bypass authentication checks, matching CWE-287. This manipulation allows an attacker to gain unauthorized access to the application and potentially elevate privileges within the system.

Affected Systems

Rebuild versions up to 4.4.7 and the beta release 4.5.0‑beta5 contain the flaw. The affected code lies in the /user/login component of the Login Endpoint. No other versions have been reported as affected.

Risk and Exploitability

The CVSS score of 6.9 indicates medium severity. The EPSS score is unavailable, but the vulnerability is publicly exploitable and can be triggered remotely. It is not listed in the CISA KEV catalog, and the vendor has not issued a patch, so the risk remains significant until a newer release is deployed.

Generated by OpenCVE AI on September 29, 2026 at 04:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Rebuild to a version newer than 4.4.7/4.5.0‑beta5 and apply any vendor patches as they become available
  • If an upgrade is not immediately possible, limit access to the /user/login endpoint through network controls or a reverse proxy, allowing only trusted internal traffic
  • Enable multi‑factor authentication for all user accounts to add an extra barrier against credential manipulation
  • Continuously monitor authentication logs for repeated or anomalous login attempts

Generated by OpenCVE AI on September 29, 2026 at 04:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 03:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in Rebuild up to 4.4.7/4.5.0-beta5. This affects an unknown part of the file /user/login of the component Login Endpoint. The manipulation leads to improper authentication. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title Rebuild Login Endpoint login improper authentication
First Time appeared Rebuild
Rebuild rebuild
Weaknesses CWE-287
CPEs cpe:2.3:a:rebuild:rebuild:*:*:*:*:*:*:*:*
Vendors & Products Rebuild
Rebuild rebuild
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:C'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-29T03:30:15.312Z

Reserved: 2026-09-28T19:04:31.218Z

Link: CVE-2026-102248

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-29T04:17:54.570

Modified: 2026-09-29T04:17:54.570

Link: CVE-2026-102248

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-29T04:30:12Z

Weaknesses