CVE-2026-19898Disclosure

LOWCVSS 2.9 · LOW

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was found in VictoriaMetrics up to 1.146.0. Impacted is the function requestHandler of the file app/vmauth/main.go of the component VMAuth Authentication Endpoint. Performing a manipulation results in improper restriction of excessive authentication attempts. The attack is possible to be carried out remotely. The complexity of an attack is rather high. The exploitability is considered difficult. The exploit has been made public and could be used. Upgrading to version 1.147.0 is recommended to address this issue. The patch is named 119ba0fb5be8024d50c5ba946599b2e69e8803ea. Upgrading the affected component is recommended.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-307CWE-799

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-08-15); latest day: 2
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01122Mentions · 2026-08-15: 2Mentions · 2026-09-22: 2Technical Details · 2026-08-15: 208-1509-22
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
By indicator
Full discourse4 posts
  • Geng Yang@geng_zast

    VMAuth is the gatekeeper for your metrics stack. In ≤ 1.146.0, it doesn't count login attempts. CVE-2026-19898 (CVSS 4.0 = 7.5): the auth endpoint has no rate limiting. Tokens and credentials get brute-forced with zero throttling — no 429, ever. https://t.co/SKJF0AAzHT

    1000052
    48 followersView on X
  • ZAST AI@zast_ai

    VMAuth is the gatekeeper for your metrics stack. In ≤ 1.146.0, it doesn't count login attempts. CVE-2026-19898 (CVSS 4.0 = 7.5): the auth endpoint applies no rate limiting or lockout. Attackers brute-force tokens/credentials unimpeded; the sink is a pure lookup with no frequency control.

    1000050
    40 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-19898 A vulnerability was found in VictoriaMetrics up to 1.146.0. Impacted is the function requestHandler of the file app/vmauth/main.go of the component VMAuth Authenticat… https://www.cve.org/CVERecord?id=CVE-2026-19898 ----- Traducción: CVE-2026-19898 Se … https://infoflow.cloud`

    Post summary

    The tweet merely reports that CVE‑2026‑19898 impacts VictoriaMetrics up to version 1.146.0, naming the vulnerable function, but offers no exploitation details, patches, or evidence of active attacks.

    0000036
    98 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-19898 A vulnerability was found in VictoriaMetrics up to 1.146.0. Impacted is the function requestHandler of the file app/vmauth/main.go of the component VMAuth Authenticat… https://www.cve.org/CVERecord?id=CVE-2026-19898

    Post summary

    CVE-2026-19898 reports a vulnerability in VictoriaMetrics up to version 1.146.0, affecting the requestHandler function in the VMAuth component; the advisory provides technical details but no PoC, exploit, or patch information.

    00000855
    57.9K followersView on X

Explore more