CVE-2025-8093: Authenticator Login - Moderately critical - Access bypass - SA-CONTRIB-2025-098
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Authenticator Login allows Authentication Bypass.This issue affects Authenticator Login: from 0.0.0 before 2.1.8.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8093?
CVE-2025-8093 is considered a critical vulnerability because it allows for authentication bypass, potentially exposing sensitive user accounts.
How do I fix CVE-2025-8093?
To fix CVE-2025-8093, update your Drupal Authenticator Login module to version 2.1.8 or later immediately.
What versions are affected by CVE-2025-8093?
CVE-2025-8093 affects all versions of the Drupal Authenticator Login module prior to 2.1.8.
What is an Authentication Bypass in the context of CVE-2025-8093?
An Authentication Bypass refers to a flaw that allows an unauthorized user to gain access to a system without proper authentication, as seen in CVE-2025-8093.
Is CVE-2025-8093 related to any particular Drupal component?
Yes, CVE-2025-8093 specifically affects the Drupal Authenticator Login module.