Skip to content
Threat Feed
high threat exploited

Improper Authentication Vulnerability in Rebuild Login Endpoint

Rebuild versions up to 4.4.7 and 4.5.0-beta5 are vulnerable to an improper authentication flaw in the login component that permits remote attackers to bypass authentication via manipulated requests.

CVE search metadata

CVE search record: CVE-2026-102248. Severity: high. CVSS: 7.3. KEV: no. Product: Rebuild (<= 4.4.7, 4.5.0-beta5), REBUILD (<= 4.4.11). Brief: Improper Authentication Vulnerability in Rebuild Login Endpoint. Brief link: https://feed.craftedsignal.io/briefs/2026-09-rebuild-auth-bypass/

What's new

  • 1. added detection rule: Detect CVE-2026-102249 - Unauthorized File Save Access Sep 29, 04:25 via nvd

A security vulnerability (CVE-2026-102248) has been identified in the Rebuild application affecting versions up to 4.4.7 and 4.5.0-beta5. The flaw resides within the Login Endpoint located at /user/login. Attackers can remotely manipulate input sent to this endpoint to trigger an authentication bypass, potentially gaining unauthorized access to the application. Public exploit code for this vulnerability is currently available, increasing the risk of active exploitation. The vendor has not responded to disclosure efforts regarding this issue. Organizations using Rebuild are advised to assess their exposure to this endpoint, as it provides a direct vector for unauthenticated access.

Impact

Successful exploitation of this vulnerability allows an unauthenticated remote attacker to bypass the application's login mechanism. This can lead to unauthorized access to user accounts, data exposure, and potential administrative control over the application, depending on the privileges of the targeted account.

Recommendation

  1. Implement strict access control lists or Web Application Firewall (WAF) rules to restrict access to /user/login if patching is not possible.
  2. Audit web server logs for high-frequency or anomalous POST requests to the /user/login path.
  3. Given the lack of a vendor response, monitor the Rebuild application for signs of unauthorized account access or unexpected administrative activity.

Immediate actions

Review web access logs for suspicious activity targeting /user/login.

SOC 24h

Threat Hunt

Anomalous successful logins from IPs that have not established a prior session or from suspicious User-Agent strings.

T1550 high medium confidence hunt now

Data: Web server access logs (method, URI, status code, source IP)

Detection coverage 1

Detect CVE-2026-102249 - Unauthorized File Save Access

high

Detects potential exploitation attempts of CVE-2026-102249 by monitoring for POST requests to the file-editor-save endpoint.

sigma tactics: initial_access techniques: T1190 sources: webserver

Detection queries are available on the platform. Get full rules →