CVE-2026-6223

9.4

Bahçelievler Muncipality · BiHayat App

The Bahçelievler Muncipality BiHayat App is vulnerable to an authentication bypass due to improper restriction of excessive authentication attempts.

Executive summary

A critical authentication bypass vulnerability in the Bahçelievler Muncipality BiHayat App allows unauthorized access, posing a severe risk to user data and system integrity.

Vulnerability

This vulnerability involves an improper restriction of excessive authentication attempts, which can be exploited by an unauthenticated attacker to bypass security controls. The flaw allows for brute force or credential stuffing attacks against the application.

Business impact

The vulnerability carries a CVSS score of 9.4, indicating a critical severity level. Successful exploitation enables unauthorized access to sensitive user accounts and administrative functions, potentially leading to widespread data compromise and a total loss of confidentiality and integrity within the application.

Remediation

Immediate Action: Update the Bahçelievler Muncipality BiHayat App to the latest version immediately to resolve the authentication restriction flaw.

Proactive Monitoring: Review access logs for patterns indicative of credential stuffing or brute force attempts, such as high frequencies of failed logins from single or distributed IP addresses.

Compensating Controls: Implement rate limiting at the network or Web Application Firewall level to block excessive authentication requests until the application patch is applied.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the critical nature of this authentication bypass and the vendor's lack of engagement, administrators must prioritize updating the BiHayat App. If an update is not feasible, restrict access to the application via secondary authentication or network-level access controls to mitigate the risk of unauthorized account takeover.

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Analyst report updated
  5. Published in the daily brief critical section

Sources

Originally found and disclosed by Onur BİLİCİ, Ferit Özner, per the CVE Program record.