<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:rebuild:rebuild:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3arebuildrebuild/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 29 Sep 2026 04:25:01 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3arebuildrebuild/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Improper Authentication Vulnerability in Rebuild Login Endpoint</title><link>https://feed.craftedsignal.io/briefs/2026-09-rebuild-auth-bypass/</link><pubDate>Tue, 29 Sep 2026 04:25:01 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-rebuild-auth-bypass/</guid><description>Rebuild versions up to 4.4.7 and 4.5.0-beta5 are vulnerable to an improper authentication flaw in the login component that permits remote attackers to bypass authentication via manipulated requests.</description><content:encoded><![CDATA[<p>A security vulnerability (CVE-2026-102248) has been identified in the Rebuild application affecting versions up to 4.4.7 and 4.5.0-beta5. The flaw resides within the Login Endpoint located at /user/login. Attackers can remotely manipulate input sent to this endpoint to trigger an authentication bypass, potentially gaining unauthorized access to the application. Public exploit code for this vulnerability is currently available, increasing the risk of active exploitation. The vendor has not responded to disclosure efforts regarding this issue. Organizations using Rebuild are advised to assess their exposure to this endpoint, as it provides a direct vector for unauthenticated access.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability allows an unauthenticated remote attacker to bypass the application's login mechanism. This can lead to unauthorized access to user accounts, data exposure, and potential administrative control over the application, depending on the privileges of the targeted account.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Implement strict access control lists or Web Application Firewall (WAF) rules to restrict access to /user/login if patching is not possible.</li>
<li>Audit web server logs for high-frequency or anomalous POST requests to the /user/login path.</li>
<li>Given the lack of a vendor response, monitor the Rebuild application for signs of unauthorized account access or unexpected administrative activity.</li>
</ol>
]]></content:encoded><category domain="severity">high</category><category domain="type">threat</category><category>authentication-bypass</category><category>web-vulnerability</category><category>cve-2026-102248</category><category>web-application</category><category>authorization-bypass</category><category>cve-2026-102249</category></item></channel></rss>