SA-CONTRIB-2026-201: Critical severity drupal/auth_login_plus vulnerability
Published Oct 7, 2026
·Updated
This module provides TOTP-based two-factor authentication (2FA) for Drupal, with an optional setting to enforce 2FA for all users site-wide. The module may allow a user log in with only a password even when site-wide enforcement of 2FA is turned on.
Credit
mouhamed rayen mansouri (w0nd3r)
Affected Software
1 affected componentFixes available
drupal/auth_login_plus<1.0.1
1.0.1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
drupal/auth_login_plusto a version that resolves this vulnerability.Fixed in 1.0.1
Event History
Oct 7, 2026
Advisory Published
via Drupal·12:00 AM
Data Sourced
via Drupal·12:00 AM
DescriptionSeverityAffected Software