CVE-2026-6223
Authentication bypass via unrestricted login attempts in Bahçelievler BiHayat App
BiHayat, the citizen-services mobile app of Bahçelievler Municipality (Istanbul, Turkey), improperly restricts excessive authentication attempts (CWE-307), allowing an authentication bypass. An attacker can send unbounded authentication attempts over the network with no privileges, no user interaction, and low attack complexity, ultimately gaining unauthorized access to accounts, with high confidentiality and integrity impact and low availability impact per the 9.4 CVSS score. Anyone using BiHayat App versions 2.1.7 through 07092026 is affected. There is no evidence of exploitation so far: no public PoC, not listed in CISA KEV, and EPSS estimates only a 0.4% probability of exploitation within 30 days. The vendor was contacted early about the disclosure but did not respond, so no confirmed patched release is available.
What to do: Update the BiHayat App to a version newer than 07092026 once the municipality publishes a fix, verifying release notes since the vendor did not respond to the disclosure. Operators of the app's backend should add rate limiting and account lockout on the authentication endpoint as a mitigation, and users should watch for signs of unauthorized account access.
| Bahçelievler Municipality BiHayat App | 2.1.7 through 07092026 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Improper restriction of excessive authentication attempts vulnerability in Bahçelievler Muncipality BiHayat App allows Authentication Bypass. This issue affects BiHayat App: from 2.1.7 through 07092026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
- Weakness
- CWE-307
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
In the news0 stories
No ingested article mentions this CVE yet.