Authentication Bypass Vulnerability in Drupal Email Login OTP
CVE-2026-16642

Currently unrated

Key Information:

Vendor

Drupal

Vendor
CVE Published:
25 August 2026

What is CVE-2026-16642?

A significant authentication bypass vulnerability exists in the Email Login OTP module for Drupal, potentially allowing unauthorized access to user accounts. This flaw can be exploited without proper authentication mechanisms being triggered, making it essential for users and administrators to update to the latest versions and apply security measures to safeguard their accounts.

Affected Version(s)

Email Login OTP *.*

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Pierre Rudloff (prudloff)
.