A brute-force facilitation issue was present in the confirmation email service. Without proper rate limiting, this endpoint could help attackers enumerate or guess credentials with less resistance.