Cyber & AI intelligence
Wasteland.
Briefs indexed2459
Issues27
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-6223 2026-09-07

CVE-2026-6223: Critical Authentication Bypass in Bahçelievler Municipality BiHayat App

"A missing rate limit on authentication attempts in the Bahçelievler Municipality BiHayat App lets unauthenticated network attackers bypass authentication, rated CVSS 9.4 (Critical)."

A missing rate limit on authentication attempts in the Bahçelievler Municipality BiHayat App lets unauthenticated network attackers bypass authentication, rated CVSS 9.4 (Critical).

What Is It

CVE-2026-6223 is an improper restriction of excessive authentication attempts vulnerability (CWE-307) in the BiHayat App, a citizen-facing application published by Bahçelievler Municipality. Because the application does not adequately limit repeated authentication attempts, an attacker can brute-force their way past the login control and achieve an authentication bypass.

The issue was reported through USOM (Turkey's national CERT), which is the assigning source for the CVE record. Notably, the advisory states that the vendor was contacted early about the disclosure but did not respond in any way.

Why It Matters

The CVSS v3.1 base score is 9.4 (Critical), with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L. Every exploitability factor is at its worst setting: the flaw is reachable over the network, attack complexity is low, no privileges are required, and no user interaction is needed. That yields a maximum exploitability subscore of 3.9.

Impact is high for both confidentiality and integrity, with low availability impact; consistent with an attacker gaining access to accounts they do not own and reading or altering the data behind them. Authentication bypass through unlimited credential guessing requires no specialized tooling, and the lack of vendor response means there is no coordinated fix timeline to point to.

There is no CISA KEV entry supplied for this CVE, so active exploitation is not confirmed in the material available.

What's Vulnerable

No CPE match strings are present in the record, so automated inventory matching against this CVE is not yet possible.

Patch Status

No patch, fixed version, or vendor remediation guidance is present in the supplied data. The CVE record status is "Received," meaning it has not yet completed NVD analysis. The vendor did not respond to the disclosure attempt, and no required action is specified. Operators of affected deployments should consult the USOM advisory below for national-CERT guidance.

Sources