ZAST.AI's engine flagged CVE-2026-19895 in OpenSourcePOS ≤ 3.4.2: login has no rate limiting, and CAPTCHA runs after the password check. That ordering turns credential correctness into an observable o
2: login has no rate limiting, and CAPTCHA runs after the password check. That ordering turns credential correctness into an observable oracle — a correct password returns a different error than a wrong one, so accounts get enumerated without solving a CAPTCHA.