Disable Login Page
2 security fixes in one update. Disable Login Page fixed 2 separate security bugs this week: 2 access bypass. One update covers all of them. The most serious, SA-CONTRIB-2026-111, is explained here and the full list is at the end of the card.
Anyone without logging in could still reach the login screen if a copy of it was saved by the website performance system before the restriction was turned on. They could not read any private data or change anything on the site.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youAny site using this module.
- Has it been used in attacksA working example has been published, so assume someone will try.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Disable Login Page to the latest release.
For developers: what the fix changed
The code change for this release could not be fetched from git.drupalcode.org.
- Moderately critical · Access bypass · SA-CONTRIB-2026-111
- Moderately critical · Access bypass · SA-CONTRIB-2026-110