Sceawere

Vulnerability Detail

CVE-2026-102248UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Rebuild Improper Authentication Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.3
Creation Date
3h ago
Vendor
n/a
Product
Rebuild
Attack Type
Improper Authentication
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability was identified in Rebuild up to 4.4.7/4.5.0-beta5. This affects an unknown part of the file /user/login of the component Login Endpoint. The manipulation leads to improper authentication. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.3",
  "pubDate": "2026-09-29T04:17:54.570Z",
  "pubdate": "2026-09-29T04:17:54.570Z",
  "executiveSummary": "A critical improper authentication vulnerability exists within the Rebuild platform's login endpoint. This security flaw enables remote attackers to bypass established authentication mechanisms, potentially gaining unauthorized access to the application. The vulnerability impacts Rebuild versions up to 4.4.7 and 4.5.0-beta5. Given that a functional exploit is publicly accessible and the vendor has remained unresponsive to disclosure attempts, the risk of active exploitation is significant. Unauthorized parties can leverage this flaw to compromise user accounts, access sensitive data, or perform unauthorized administrative actions without providing valid credentials. The attack is executable remotely, requiring no prior authentication, which significantly increases the attack surface and potential business impact.",
  "technicalDetails": "The vulnerability resides in the /user/login file, which functions as the primary authentication portal for the Rebuild application. The defect stems from an improper implementation of authentication logic within this endpoint, failing to correctly validate credentials or session state transitions. Because the authentication flow does not adequately verify the legitimacy of the incoming request or the provided user identifiers, it permits the bypass of standard security constraints.\nThe root cause is identified as a flaw in the input processing or authentication verification routines within the /user/login component. This allows an attacker to manipulate authentication requests to force the application to treat an unauthorized session as legitimate. The lack of robust validation allows the endpoint to return an authenticated session context to the requester despite the absence of valid credentials.\nAttackers can trigger this vulnerability by crafting malicious HTTP requests directed at the /user/login endpoint. The attack flow involves submitting a specifically crafted request that exploits the logic flaw to bypass the authentication routine entirely. Because the endpoint improperly handles the request parameters or the logic flow associated with user validation, the application incorrectly grants access to the session layer.\nThe exploitation is conducted remotely over the network, requiring no special privileges or pre-existing account access. Once the exploit is initiated and the authentication barrier is successfully bypassed, the attacker effectively impersonates a legitimate user or potentially an administrator, depending on the scope of the bypassed authorization. The post-exploitation impact includes full account takeovers, unauthorized access to proprietary data stored within the Rebuild ecosystem, and the ability to manipulate system settings or user data. The availability of public exploit code facilitates the execution of this attack by malicious actors with minimal technical barriers, rendering the system highly vulnerable to unauthorized access and potential data exfiltration or system modification."
}
CVE-2026-102248: Rebuild Improper Authentication Vulnerability (HIGH Severity, CVSS: 7.3) | Sceawere