Skip to content
Threat Feed
critical advisory

Authentication Bypass Vulnerability in BiHayat App

The BiHayat App contains a flaw in authentication rate limiting that permits attackers to bypass login protections and gain unauthorized system access.

CVE search metadata

CVE search record: CVE-2026-6223. Severity: critical. CVSS: 9.4. KEV: no. Product: BiHayat App (2.1.7 through 07092026). Brief: Authentication Bypass Vulnerability in BiHayat App. Brief link: https://feed.craftedsignal.io/briefs/2026-09-bihayat-auth-bypass/

The BiHayat App, developed by the Bahçelievler Municipality, contains a vulnerability (CVE-2026-6223) categorized as an improper restriction of excessive authentication attempts. This flaw allows remote, unauthenticated attackers to bypass authentication controls, effectively neutralizing login security measures. The vulnerability impacts application versions 2.1.7 through 07092026. As of the disclosure date, the vendor has not responded to vulnerability reports, leaving affected systems at high risk of unauthorized access. Defenders should monitor web logs for anomalous login patterns or spikes in authentication requests originating from single source IPs, which may indicate exploitation of this bypass mechanism.

Impact

Successful exploitation allows an unauthenticated attacker to gain unauthorized access to the application, potentially exposing user data or allowing administrative actions. Given the critical CVSS 9.4 severity, the risk of data exfiltration and account takeover is high for organizations relying on this application for citizen services or internal municipality management.

Recommendation

Identify and inventory all instances of BiHayat App 2.1.7 or later currently in production environments. Given the lack of a vendor patch, restrict access to the application via network-level controls or a Web Application Firewall (WAF) until the vulnerability is addressed. Implement rate limiting at the WAF level to block excessive authentication attempts, as this serves as a temporary compensating control against the underlying authentication bypass.


Immediate actions

Inventory all BiHayat App deployments and restrict public access

IT Operations 24h

Mitigations

Implement WAF rate-limiting for all authentication endpoints associated with BiHayat App

immediate IT Operations

CVE-2026-6223