ZeroHour

CVE-2026-6223

Authentication bypass via unrestricted login attempts in Bahçelievler BiHayat App

CVSS 3.1
9.4 critical
EPSS
<1%p37
Published
()
Modified
AI analysis

BiHayat, the citizen-services mobile app of Bahçelievler Municipality (Istanbul, Turkey), improperly restricts excessive authentication attempts (CWE-307), allowing an authentication bypass. An attacker can send unbounded authentication attempts over the network with no privileges, no user interaction, and low attack complexity, ultimately gaining unauthorized access to accounts, with high confidentiality and integrity impact and low availability impact per the 9.4 CVSS score. Anyone using BiHayat App versions 2.1.7 through 07092026 is affected. There is no evidence of exploitation so far: no public PoC, not listed in CISA KEV, and EPSS estimates only a 0.4% probability of exploitation within 30 days. The vendor was contacted early about the disclosure but did not respond, so no confirmed patched release is available.

What to do: Update the BiHayat App to a version newer than 07092026 once the municipality publishes a fix, verifying release notes since the vendor did not respond to the disclosure. Operators of the app's backend should add rate limiting and account lockout on the authentication endpoint as a mitigation, and users should watch for signs of unauthorized account access.

Affected
Bahçelievler Municipality BiHayat App2.1.7 through 07092026
Estimated exposure
unknown — no public install figures; plausibly at most tens of thousands of users of a single Istanbul district's municipal app — No public download or active-user data exists for BiHayat; it serves residents of a single Istanbul district (roughly 600,000 population), so the user base is likely far below mass scale but cannot be quantified from available data.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper restriction of excessive authentication attempts vulnerability in Bahçelievler Muncipality BiHayat App allows Authentication Bypass. This issue affects BiHayat App: from 2.1.7 through 07092026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

Weakness
CWE-307
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L

In the news

No ingested article mentions this CVE yet.