CVE-2025-8995: Authenticator Login - Highly critical - Access bypass - SA-CONTRIB-2025-096
Published Aug 15, 2025
·Updated
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Authenticator Login allows Authentication Bypass.This issue affects Authenticator Login: from 0.0.0 before 2.1.4.
Affected Software
2 affected components
Drupal Authenticator Login>0.0.0, <2.1.4
Authenticator Login Project Authenticator Login Drupal<2.1.4
Event History
Aug 15, 2025
CVE Published
via MITRE·04:27 PM
Data Sourced
via MITRE·04:27 PM
DescriptionWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Mar 11, 57926
Event
via FIRST·12:47 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-8995?
CVE-2025-8995 is classified as a critical vulnerability due to its potential for authentication bypass.
2
How do I fix CVE-2025-8995?
To address CVE-2025-8995, upgrade the Drupal Authenticator Login module to version 2.1.4 or later.
3
What versions of Drupal Authenticator Login are affected by CVE-2025-8995?
CVE-2025-8995 affects all versions of Drupal Authenticator Login from 0.0.0 up to, but not including, 2.1.4.
4
Can CVE-2025-8995 lead to unauthorized access?
Yes, CVE-2025-8995 can allow attackers to bypass authentication and gain unauthorized access to the system.
5
Is it safe to use an affected version of the Drupal Authenticator Login module?
Using an affected version of the Drupal Authenticator Login module poses significant security risks and is not safe.