SA-CONTRIB-2026-197: Critical severity drupal/auth_login_plus vulnerability
This module provides TOTP-based two-factor authentication (2FA) for Drupal. The module doesn't enforce the second factor when a user logs in with Drupal core's one-time login link. This vulnerability is mitigated by the fact that an attacker must have access to a valid one-time login link for a victim's account.
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
drupal/auth_login_plusto a version that resolves this vulnerability.Fixed in 1.0.1