Improper Authentication Vulnerability in Rebuild Login Endpoint
Rebuild versions up to 4.4.7 and 4.5.0-beta5 are vulnerable to an improper authentication flaw in the login component that permits remote attackers to bypass authentication via manipulated requests.
CVE search metadata
CVE search record: CVE-2026-102248. Severity: high. CVSS: 7.3. KEV: no. Product: Rebuild (<= 4.4.7, 4.5.0-beta5), REBUILD (<= 4.4.11). Brief: Improper Authentication Vulnerability in Rebuild Login Endpoint. Brief link: https://feed.craftedsignal.io/briefs/2026-09-rebuild-auth-bypass/
What's new
- 1. added detection rule: Detect CVE-2026-102249 - Unauthorized File Save Access Sep 29, 04:25 via nvd
A security vulnerability (CVE-2026-102248) has been identified in the Rebuild application affecting versions up to 4.4.7 and 4.5.0-beta5. The flaw resides within the Login Endpoint located at /user/login. Attackers can remotely manipulate input sent to this endpoint to trigger an authentication bypass, potentially gaining unauthorized access to the application. Public exploit code for this vulnerability is currently available, increasing the risk of active exploitation. The vendor has not responded to disclosure efforts regarding this issue. Organizations using Rebuild are advised to assess their exposure to this endpoint, as it provides a direct vector for unauthenticated access.
Impact
Successful exploitation of this vulnerability allows an unauthenticated remote attacker to bypass the application's login mechanism. This can lead to unauthorized access to user accounts, data exposure, and potential administrative control over the application, depending on the privileges of the targeted account.
Recommendation
- Implement strict access control lists or Web Application Firewall (WAF) rules to restrict access to /user/login if patching is not possible.
- Audit web server logs for high-frequency or anomalous POST requests to the /user/login path.
- Given the lack of a vendor response, monitor the Rebuild application for signs of unauthorized account access or unexpected administrative activity.
Immediate actions
Review web access logs for suspicious activity targeting /user/login.
Threat Hunt
Anomalous successful logins from IPs that have not established a prior session or from suspicious User-Agent strings.
Data: Web server access logs (method, URI, status code, source IP)
Detection coverage 1
Detect CVE-2026-102249 - Unauthorized File Save Access
highDetects potential exploitation attempts of CVE-2026-102249 by monitoring for POST requests to the file-editor-save endpoint.
Detection queries are available on the platform. Get full rules →