Authentication Bypass Vulnerability in Drupal Email TFA
CVE-2025-12760
5.4MEDIUM
What is CVE-2025-12760?
The vulnerability in Drupal's Email TFA allows attackers to bypass authentication through an alternate path or channel. Affected versions include Email TFA prior to 2.0.6, which could enable unauthenticated users to access protected functionality. It is essential for users to apply the latest updates to safeguard their systems from potential exploitation.
Affected Version(s)
Email TFA 0.0.0 < 2.0.6
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Pierre Rudloff (prudloff)
abdulaziz zaid
Greg Knaddison (greggles)
Juraj Nemec (poker10)
Pierre Rudloff (prudloff)
