CVE-2026-6816
Analyzed
Analyzed - Analysis Complete
Access Bypass in Drupal TFA Basic Plugins
Publication date: 2026-05-28
Last updated on: 2026-06-01
Assigner: Drupal.org
Description
Description
An access bypass vulnerability in Drupal TFA Basic Plugins allows users with the administer users permission to view or generate recovery codes for other users.
This issue affects TFA Basic Plugins: from 7.x-1.0 through 7.x-1.2.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| tfa_basic_plugins_project | tfa_basic_plugins | From 7.x-1.0 (inc) to 7.x-1.3 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-267 | A particular privilege, role, capability, or right can be used to perform unsafe actions that were not intended, even when it is assigned to the correct entity. |