CVE-2026-19895 | opensourcepos Open Source Point of Sale up to 3.4.2 Login Endpoint app/Config/Filters.php Login::index excessive authentication (Issue 4583 / EUVD-2026-59760)
A vulnerability, which was classified as problematic, was found in opensourcepos Open Source Point of Sale up to 3.4.2. This affects the function Login::index of the file app/Config/Filters.php of the component Login Endpoint. The manipulation results in improper restriction of excessive authentication attempts.
This vulnerability is cataloged as CVE-2026-19895. The attack may be launched remotely. Furthermore, there is an exploit available.
The project was informed of the problem early through an issue report but has not responded yet.