Authentication Bypass Vulnerability in Drupal Email TFA
CVE-2025-12760

Currently unrated

Key Information:

Vendor

Drupal

Status
Vendor
CVE Published:
18 November 2025

What is CVE-2025-12760?

The vulnerability in Drupal's Email TFA allows attackers to bypass authentication through an alternate path or channel. Affected versions include Email TFA prior to 2.0.6, which could enable unauthenticated users to access protected functionality. It is essential for users to apply the latest updates to safeguard their systems from potential exploitation.

Affected Version(s)

Email TFA 0.0.0 < 2.0.6

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Pierre Rudloff (prudloff)
abdulaziz zaid
Greg Knaddison (greggles)
Juraj Nemec (poker10)
Pierre Rudloff (prudloff)
.
CVE-2025-12760 : Authentication Bypass Vulnerability in Drupal Email TFA