CVE-2026-6223
9.4Bahçelievler Muncipality · BiHayat App
The Bahçelievler Muncipality BiHayat App is vulnerable to an authentication bypass due to improper restriction of excessive authentication attempts.
Executive summary
A critical authentication bypass vulnerability in the Bahçelievler Muncipality BiHayat App allows unauthorized access, posing a severe risk to user data and system integrity.
Vulnerability
This vulnerability involves an improper restriction of excessive authentication attempts, which can be exploited by an unauthenticated attacker to bypass security controls. The flaw allows for brute force or credential stuffing attacks against the application.
Business impact
The vulnerability carries a CVSS score of 9.4, indicating a critical severity level. Successful exploitation enables unauthorized access to sensitive user accounts and administrative functions, potentially leading to widespread data compromise and a total loss of confidentiality and integrity within the application.
Remediation
Immediate Action: Update the Bahçelievler Muncipality BiHayat App to the latest version immediately to resolve the authentication restriction flaw.
Proactive Monitoring: Review access logs for patterns indicative of credential stuffing or brute force attempts, such as high frequencies of failed logins from single or distributed IP addresses.
Compensating Controls: Implement rate limiting at the network or Web Application Firewall level to block excessive authentication requests until the application patch is applied.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the critical nature of this authentication bypass and the vendor's lack of engagement, administrators must prioritize updating the BiHayat App. If an update is not feasible, restrict access to the application via secondary authentication or network-level access controls to mitigate the risk of unauthorized account takeover.
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Analyst report updated
- Published in the daily brief critical section
Sources
Originally found and disclosed by Onur BİLİCİ, Ferit Özner, per the CVE Program record.