CVE-2026-71213
Critical · CVSS 9.1- CVSS
- 9.1
- nvd
- EPSS
- 0.36%
- 29th pct
- KEV
- No
- Class
- oss containerizable
- CWE-307
Description
Typemill's login endpoint (POST /tm/login, ControllerWebAuth::login) performs no rate-limiting, failed-attempt counting, or account lockout when captcha is disabled, which is the default configuration. An unauthenticated attacker can send unlimited password-guessing requests against any account, including administrators, with no throttling.
References
Status: profiled · ingested 2026-08-10T18:00:50.000Z