CVE-2026-19897
Received Received - Intake

Improper Authentication in Dtale Login Endpoint

Vulnerability report for CVE-2026-19897, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-15

Last updated on: 2026-08-15

Assigner: VulDB

Description

A vulnerability has been found in mangroup dtale up to 3.22.0. This issue affects the function Login of the file dtale/auth.py of the component Login Endpoint. Such manipulation leads to improper restriction of excessive authentication attempts. The attack can be executed remotely. This attack is characterized by high complexity. The exploitability is assessed as difficult. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-15
Last Modified
2026-08-15
Generated
2026-08-16
AI Q&A
2026-08-15
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
mangroup dtale to 3.22.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-307 The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.
CWE-799 The product does not properly limit the number or frequency of interactions that it has with an actor, such as the number of incoming requests.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the Login function in dtale/auth.py of mangroup dtale up to version 3.22.0. It allows excessive authentication attempts due to improper restrictions, enabling remote attacks with high complexity and difficult exploitability. The issue was publicly disclosed and reported to the project but remains unaddressed.

Impact Analysis

An attacker could exploit this to repeatedly attempt logins without proper restrictions, potentially gaining unauthorized access to sensitive data or functionality. The high complexity and difficulty reduce the risk but do not eliminate it entirely.

Compliance Impact

This vulnerability could lead to unauthorized access, violating data protection principles in GDPR and HIPAA. It may result in non-compliance due to insufficient authentication controls, potentially leading to data breaches and regulatory penalties.

Mitigation Strategies

Immediately update mangroup dtale to a version beyond 3.22.0 to address the improper authentication restriction issue. If an update is unavailable, consider disabling the Login Endpoint in dtale/auth.py or implementing rate limiting to prevent excessive authentication attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19897. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart