Sceawere

Vulnerability Detail

CVE-2026-19898UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

VictoriaMetrics VMAuth Authentication Rate Limiting Bypass

Vulnerability Metadata

Severity
Low
Score / CVSS
3.7
Creation Date
2h ago
Vendor
n/a
Product
VictoriaMetrics
Attack Type
Improper Restriction of Excessive Authentication Attempts
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
HIGH

Narrative and Response

Description

A vulnerability was found in VictoriaMetrics up to 1.146.0. Impacted is the function requestHandler of the file app/vmauth/main.go of the component VMAuth Authentication Endpoint. Performing a manipulation results in improper restriction of excessive authentication attempts. The attack is possible to be carried out remotely. The complexity of an attack is rather high. The exploitability is considered difficult. The exploit has been made public and could be used. Upgrading to version 1.147.0 is recommended to address this issue. The patch is named 119ba0fb5be8024d50c5ba946599b2e69e8803ea. Upgrading the affected component is recommended.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "3.7",
  "pubDate": "2026-08-15T16:16:39.230Z",
  "pubdate": "2026-08-15T16:16:39.230Z",
  "executiveSummary": "A vulnerability has been identified in VictoriaMetrics up to version 1.146.0 affecting the VMAuth authentication endpoint. Specifically, the flaw resides in the requestHandler function located within the app/vmauth/main.go file.\nThe vulnerability involves improper restriction of excessive authentication attempts, allowing potential threat actors to bypass intended rate-limiting mechanisms on authentication routines.\nThe impact of this security flaw includes exposure to brute-force attacks and credential stuffing against protected downstream services managed by VMAuth.\nThe attack vector is remote, enabling unauthenticated or remote malicious actors to interact with the authentication endpoint over the network.\nHowever, the attack complexity is considered rather high, and the exploitability is classified as difficult. Furthermore, a public exploit has been released and could potentially be leveraged by attackers.\nOrganizations utilizing affected versions of VictoriaMetrics face operational risks related to unauthorized access attempts and potential resource exhaustion if authentication endpoints are systematically flooded.\nTo remediate this vulnerability, immediate upgrading to version 1.147.0 is strongly recommended by the vendor, applying the official patch referenced as 119ba0fb5be8024d50c5ba946599b2e69e8803ea.",
  "technicalDetails": "The vulnerability stems from insufficient controls within the VMAuth authentication endpoint regarding the frequency and volume of authentication requests handled by the application.\nThe root cause is located in the requestHandler function within app/vmauth/main.go, where incoming proxy requests fail to properly enforce restrictions on excessive authentication attempts.\nThe affected component is the VMAuth Authentication Endpoint, impacting all VictoriaMetrics deployments running software versions up to 1.146.0.\nBecause the vulnerable functionality is exposed via network interfaces to handle remote client traffic, the attack surface is remotely accessible.\nThe exploitation method relies on sending a high volume of crafted authentication payloads or rapid sequential authentication requests to the endpoint without encountering the expected throttling or rate-limiting enforcement.\nThe attack flow typically involves a remote adversary targeting the exposed VMAuth server and transmitting automated authentication sequences that attempt to bypass restrictions designed to mitigate brute-force and credential-stuffing vectors.\nDue to the lack of proper request throttling logic in the vulnerable requestHandler implementation, the system processes excessive authentication attempts greedily, leading to potential security degradation.\nThe exploitability of this vulnerability is characterized as difficult with a rather high attack complexity, meaning successful exploitation may require specific timing, conditions, or supporting tooling, despite the existence of a public exploit.\nPost-exploitation impact encompasses unauthorized brute-forcing of credentials, potential compromise of downstream protected services, and increased risk of denial-of-service conditions due to authentication resource exhaustion."
}
CVE-2026-19898: VictoriaMetrics VMAuth Authentication Rate Limiting Bypass (LOW Severity, CVSS: 3.7) - Sceawere