CVE-2026-30777
Received
Received - Intake
MFA Bypass in EC-CUBE Allows Unauthorized Admin Access
Publication date: 2026-03-05
Last updated on: 2026-03-09
Assigner: JPCERT/CC
Description
Description
EC-CUBE provided by EC-CUBE CO.,LTD. contains a multi-factor authentication (MFA) bypass vulnerability. An attacker who has obtained a valid administrator ID and password may be able to bypass two-factor authentication and gain unauthorized access to the administrative page.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| ec-cube | ec-cube | 4.1.2 |
| ec-cube | ec-cube | 4.1.2 |
| ec-cube | ec-cube | From 4.1.0 (inc) to 4.1.2 (exc) |
| ec-cube | ec-cube | From 4.2.0 (inc) to 4.2.3 (exc) |
| ec-cube | ec-cube | From 4.3.0 (inc) to 4.3.1 (exc) |
| ec-cube | ec-cube | 4.1.2 |
| ec-cube | ec-cube | 4.1.2 |
| ec-cube | ec-cube | 4.1.2 |
| ec-cube | ec-cube | 4.2.3 |
| ec-cube | ec-cube | 4.2.3 |
| ec-cube | ec-cube | 4.3.1 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-288 | The product requires authentication, but the product has an alternate path or channel that does not require authentication. |