CVE-2026-19895
Received Received - Intake

Brute Force Authentication Bypass in OpenSourcePOS

Vulnerability report for CVE-2026-19895, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-15

Last updated on: 2026-08-15

Assigner: VulDB

Description

A vulnerability was detected in opensourcepos Open Source Point of Sale up to 3.4.2. This affects the function Login::index of the file app/Config/Filters.php of the component Login Endpoint. The manipulation results in improper restriction of excessive authentication attempts. The attack may be launched remotely. The attack requires a high level of complexity. It is indicated that the exploitability is difficult. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-15
Last Modified
2026-08-15
Generated
2026-08-16
AI Q&A
2026-08-15
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
opensourcepos open_source_point_of_sale to 3.4.2 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-307 The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.
CWE-799 The product does not properly limit the number or frequency of interactions that it has with an actor, such as the number of incoming requests.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Open Source Point of Sale (opensourcepos) versions up to 3.4.2. It is located in the Login::index function of the app/Config/Filters.php file, specifically in the Login Endpoint. The issue allows excessive authentication attempts without proper restrictions, potentially enabling unauthorized access attempts.

Impact Analysis

An attacker could exploit this to repeatedly attempt logins, potentially gaining unauthorized access to the point-of-sale system. This may lead to data breaches, financial fraud, or disruption of sales operations. The exploit is public and requires high complexity but is still a risk.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive customer or transaction data, violating GDPR (data protection) and HIPAA (health information privacy) requirements. Non-compliance may result in legal penalties, fines, or reputational damage.

Mitigation Strategies

Update Open Source Point of Sale to the latest version beyond 3.4.2 if available. Implement rate limiting on the login endpoint to prevent excessive authentication attempts. Monitor login attempts for unusual activity and block suspicious IPs.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19895. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart