CVE-2025-12760: Email TFA - Moderately critical - Access bypass - SA-CONTRIB-2025-115
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Email TFA allows Functionality Bypass. This issue affects Email TFA: from 0.0.0 before 2.0.6.
Other sources
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Email TFA allows Functionality Bypass.This issue affects Email TFA: from 0.0.0 before 2.0.6.
— MITRE
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12760?
CVE-2025-12760 is classified as a medium severity vulnerability due to its ability to allow authentication bypass.
How do I fix CVE-2025-12760?
To fix CVE-2025-12760, upgrade to Drupal Email TFA version 2.0.6 or later.
What software is affected by CVE-2025-12760?
CVE-2025-12760 affects versions of Drupal Email TFA from 0.0.0 up to, but not including, 2.0.6.
What type of vulnerability is CVE-2025-12760?
CVE-2025-12760 is an authentication bypass vulnerability that allows functionality bypass in Drupal Email TFA.
Can CVE-2025-12760 be exploited remotely?
Yes, CVE-2025-12760 can potentially be exploited remotely if an attacker can access the affected Drupal Email TFA functionality.