Drupal security updates, in plain English · Module

Disable Login Page

1,613 sites report using it · on drupal.org · 2 security updates explained here

This module hides the standard website login screen from visitors unless they know a secret web address.

Below is every security update for Disable Login Page that this site has covered, newest first. Each one says who could exploit it, whether it applies to your site, how urgent it is, and what to tell your developer. If your site uses this module and you are not sure which version, that is the first question to ask whoever looks after it.

Disable Login Page

Moderately critical · 1,613 sites report using it · 2 security fixes · Week of 26 August 2026

2 security fixes in one update. Disable Login Page fixed 2 separate security bugs this week: 2 access bypass. One update covers all of them. The most serious, SA-CONTRIB-2026-111, is explained here and the full list is at the end of the card.

Anyone without logging in could still reach the login screen if a copy of it was saved by the website performance system before the restriction was turned on. They could not read any private data or change anything on the site.

  • Who could do thisAnyone visiting the site. No login needed.
  • Does it apply to youAny site using this module.
  • Has it been used in attacksA working example has been published, so assume someone will try.
  • How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.

Tell your developerUpdate Disable Login Page to the latest release.

For developers: what the fix changed

The code change for this release could not be fetched from git.drupalcode.org.

All 2 security bugs this update fixes, worst first. Each link is the drupal.org notice for that one.

Disable Login Page

Critical · 1,613 sites report using it · SA-CONTRIB-2026-091 · on drupal.org · Week of 29 July 2026

This project has been withdrawn because of a security problem its maintainer did not fix. The details are not published. It should be treated as unsafe to keep.

  • Who could do thisOnly someone with an administrator login.
  • Does it apply to youAny site using this module.
  • Has it been used in attacksNo sign of it.
  • How urgentThe Drupal security team has withdrawn this module because its maintainer did not fix a known problem. The only remedy is to remove or replace it.

Tell your developerRemove or replace Disable Login Page. There is no fixed version.

For developers: what the fix changed

The module has been withdrawn, so there is no fixed release to compare.

Not sure what your site is running?

Send me your Drupal site's address.

I'll tell you what I can see from outside, what the Drupal 10 end of life on 9 December means for it, and what it would cost to have me keep it patched. There's no charge for that and no obligation. peter@peterbrady.co.uk


Get in touch

Tell me who you are, what your organisation does, and what you need. That might be a Drupal site that needs looking after, an upgrade to get done before December, or an agency that needs Drupal cover.

If I can help, I'll say so and suggest a call. If I can't, I'll tell you straight away rather than waste your time.

peter@peterbrady.co.uk

For context: I work mainly with UK charities, membership bodies and research organisations, and with the agencies that look after their websites. Not recruiters.

Or start smaller and connect with me on LinkedIn. That's where I post what I find digging around in charity and grants data, and where the free tools turn up first.