A vulnerability was found in VictoriaMetrics up to 1.146.0. It has been classified as problematic. Impacted is the function
requestHandler of the file app/vmauth/main.go of the component VMAuth Authentication Endpoint. Performing a manipulation results in improper restriction of excessive authentication attempts.
This vulnerability is reported as CVE-2026-19898. The attack is possible to be carried out remotely. Moreover, an exploit is present.
Upgrading the affected component is recommended.