{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/rebuild/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:rebuild:rebuild:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-102248"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Rebuild (\u003c= 4.4.7, 4.5.0-beta5)","REBUILD (\u003c= 4.4.11)"],"_cs_severities":["high"],"_cs_tags":["authentication-bypass","web-vulnerability","cve-2026-102248","web-application","authorization-bypass","cve-2026-102249"],"_cs_type":"threat","_cs_vendors":["Rebuild"],"content_html":"\u003cp\u003eA security vulnerability (CVE-2026-102248) has been identified in the Rebuild application affecting versions up to 4.4.7 and 4.5.0-beta5. The flaw resides within the Login Endpoint located at /user/login. Attackers can remotely manipulate input sent to this endpoint to trigger an authentication bypass, potentially gaining unauthorized access to the application. Public exploit code for this vulnerability is currently available, increasing the risk of active exploitation. The vendor has not responded to disclosure efforts regarding this issue. Organizations using Rebuild are advised to assess their exposure to this endpoint, as it provides a direct vector for unauthenticated access.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows an unauthenticated remote attacker to bypass the application's login mechanism. This can lead to unauthorized access to user accounts, data exposure, and potential administrative control over the application, depending on the privileges of the targeted account.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eImplement strict access control lists or Web Application Firewall (WAF) rules to restrict access to /user/login if patching is not possible.\u003c/li\u003e\n\u003cli\u003eAudit web server logs for high-frequency or anomalous POST requests to the /user/login path.\u003c/li\u003e\n\u003cli\u003eGiven the lack of a vendor response, monitor the Rebuild application for signs of unauthorized account access or unexpected administrative activity.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-29T04:25:11Z","date_published":"2026-09-29T04:25:01Z","id":"https://feed.craftedsignal.io/briefs/2026-09-rebuild-auth-bypass/","summary":"Rebuild versions up to 4.4.7 and 4.5.0-beta5 are vulnerable to an improper authentication flaw in the login component that permits remote attackers to bypass authentication via manipulated requests.","title":"Improper Authentication Vulnerability in Rebuild Login Endpoint","url":"https://feed.craftedsignal.io/briefs/2026-09-rebuild-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Rebuild","version":"https://jsonfeed.org/version/1.1"}