CVE-2026-19895Disclosure

LOWCVSS 2.9 · LOW

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was detected in opensourcepos Open Source Point of Sale up to 3.4.2. This affects the function Login::index of the file app/Config/Filters.php of the component Login Endpoint. The manipulation results in improper restriction of excessive authentication attempts. The attack may be launched remotely. The attack requires a high level of complexity. It is indicated that the exploitability is difficult. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-307CWE-799

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-08-15); latest day: 2
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01122Mentions · 2026-08-15: 2Mentions · 2026-09-02: 2Technical Details · 2026-08-15: 2Technical Details · 2026-09-02: 208-1509-02
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-08-152
Disclosure2
2026-09-022
Disclosure1General1
Full discourse4 posts
  • Geng Yang@geng_zast
    Disclosure

    CVE-2026-19895: the login endpoint has no brute-force protection, and CAPTCHA is validated after the password. That makes "password is correct" a server-side oracle.

    Post summary

    The note highlights that CVE‑2026‑19895 lacks brute‑force protection and validates the CAPTCHA after password verification, exposing a server‑side oracle vulnerability.

    1000047
    48 followersView on X
  • ZAST AI@zast_ai
    General

    https://ZAST.AI has verified CVE-2026-19895 in OpenSourcePOS ≤ 3.4.2 — a credential-enumeration flaw (CVSS 3.1 = 5.3). https://t.co/stXRPFJSg2

    Post summary

    ZAST.AI confirms CVE-2026-19895 as a credential‑enumeration flaw in OpenSourcePOS 3.4.2 or earlier, rated CVSS 3.1: 5.3, with no PoC, exploit, or patch details provided.

    1000053
    39 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-19895 A vulnerability was detected in opensourcepos Open Source Point of Sale up to 3.4.2. This affects the function Login::index of the file app/Config/Filters.php of the … https://www.cve.org/CVERecord?id=CVE-2026-19895

    Post summary

    The post announces CVE-2026-19895, detailing a vulnerability in Open Source Point of Sale affecting the Login::index function up to version 3.4.2, with no PoC, exploit, or patch information provided.

    00010988
    57.9K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-19895 A vulnerability was detected in opensourcepos Open Source Point of Sale up to 3.4.2. This affects the function Login::index of the file app/Config/Filters.php of the … https://www.cve.org/CVERecord?id=CVE-2026-19895 ----- Traducción: CVE-2026-19895 Se … https://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑19895, a vulnerability in OpenSourcePOS versions up to 3.4.2, affecting the Login::index function in app/Config/Filters.php.

    0000029
    98 followersView on X

Explore more