SA-CONTRIB-2026-124: Critical severity drupal/otp_verification vulnerability
Published Sep 2, 2026
·Updated
This module enables you to add extra layer of verification for user registration. The module doesn't sufficiently validate user-supplied input resulting in an account takeover vulnerability.
Credit
Drew Webber (mcdruid)(the Drupal Security Team)
Affected Software
1 affected componentFixes available
drupal/otp_verification<8.x-2.4
8.x-2.4
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
drupal/otp_verificationto a version that resolves this vulnerability.Fixed in 8.x-2.4
Event History
Sep 2, 2026
Advisory Published
via Drupal·12:00 AM
Data Sourced
via Drupal·12:00 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
Which deployments should be prioritized for review?
Review Drupal deployments that use the otp_verification module. The advisory identifies this module as the affected software.
2
How should this issue be prioritized?
Treat it as critical: the advisory assigns severity 9 and risk 42, and identifies account takeover as the impact.