← Back to overview

CVE-2026-6223 describes an improper restriction of excessive authentication attempts vulnerability in the Bahçelievler Municipality BiHayat mobile application. This flaw allows attackers to perform authentication bypass, potentially gaining unauthorized access to user accounts. The affected versions span from 2.1.7 through 07092026. The vulnerability is classified under CWE for brute-force or unlimited login attempts without lockout mechanisms. The vendor was contacted prior to public disclosure but did not respond. The disclosure was published via the Turkish cybersecurity authority siberguvenlik.gov.tr as well as the NVD. No patch or mitigation has been confirmed from the vendor side.

Affected products

  • Bahçelievler Municipality BiHayat App

Related CVE's

  • CVE-2026-6223

Categories

  • Identity & Access
  • Mobile & IoT