---
id: CVE-2026-102248
title: A vulnerability was identified in Rebuild up to 4.4.7/4.5.0-beta5
summary: >-
  A vulnerability was identified in Rebuild up to 4.4.7/4.5.0-beta5. This
  affects an unknown part of the file /user/login of the component Login
  Endpoint. The manipulation leads to improper authentication. It is possible to
  initiate the at…
severity: high
cvss: 7.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-287
product: Rebuild
affected:
  - Rebuild 4.4.0
  - Rebuild 4.4.1
  - Rebuild 4.4.2
  - Rebuild 4.4.3
  - Rebuild 4.4.4
  - Rebuild 4.4.5
  - Rebuild 4.4.6
  - Rebuild 4.4.7
  - Rebuild 4.5.0-beta1
  - Rebuild 4.5.0-beta2
  - Rebuild 4.5.0-beta3
  - Rebuild 4.5.0-beta4
  - Rebuild 4.5.0-beta5
published: '2026-09-29'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T04:17:54.570'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-102248'
references:
  - url: 'https://github.com/ASantsSec/CVE/issues/25'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-102248'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/933708'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/411150'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/411150/cti'
    label: cna@vuldb.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-29T04:27:15.485Z'
---

## Overview

A vulnerability was identified in Rebuild up to 4.4.7/4.5.0-beta5. This affects an unknown part of the file /user/login of the component Login Endpoint. The manipulation leads to improper authentication. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
