CVE-2026-19898
Received Received - Intake

Authentication Bypass in VictoriaMetrics VMAuth

Vulnerability report for CVE-2026-19898, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-15

Last updated on: 2026-08-15

Assigner: VulDB

Description

A vulnerability was found in VictoriaMetrics up to 1.146.0. Impacted is the function requestHandler of the file app/vmauth/main.go of the component VMAuth Authentication Endpoint. Performing a manipulation results in improper restriction of excessive authentication attempts. The attack is possible to be carried out remotely. The complexity of an attack is rather high. The exploitability is considered difficult. The exploit has been made public and could be used. Upgrading to version 1.147.0 is recommended to address this issue. The patch is named 119ba0fb5be8024d50c5ba946599b2e69e8803ea. Upgrading the affected component is recommended.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-15
Last Modified
2026-08-15
Generated
2026-08-16
AI Q&A
2026-08-16
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
victoriametrics victoriametrics to 1.146.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-307 The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.
CWE-799 The product does not properly limit the number or frequency of interactions that it has with an actor, such as the number of incoming requests.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects VictoriaMetrics up to version 1.146.0, specifically in the VMAuth Authentication Endpoint. It involves improper restriction of excessive authentication attempts due to a flaw in the requestHandler function of app/vmauth/main.go. The issue allows remote attackers to exploit weak authentication mechanisms with a high attack complexity.

Detection Guidance

Detecting this vulnerability requires checking the version of VictoriaMetrics running on your system. If you are using version 1.146.0 or earlier, the system is vulnerable. Run the command 'curl http://<victoriametrics-address>:8428/-/version' to check the installed version.

Impact Analysis

The vulnerability could allow unauthorized users to repeatedly attempt authentication, potentially gaining access to sensitive data or functions if weak credentials are used. The public exploit increases the risk of real-world attacks. Upgrading to version 1.147.0 or applying the patch is recommended to mitigate this risk.

Mitigation Strategies

Upgrade VictoriaMetrics to version 1.147.0 or later immediately. Apply the patch 119ba0fb5be8024d50c5ba946599b2e69e8803ea if upgrading is not feasible. Ensure no exposed authentication endpoints are accessible without proper restrictions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19898. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart