5.1
CVE-2026-6816
- EPSS 0.32%
- Veröffentlicht 28.05.2026 22:50:49
- Zuletzt bearbeitet 01.06.2026 17:15:34
- Quelle mlhess@drupal.org
- CVE-Watchlists
- Unerledigt
TFA Basic Plugins - Access Bypass
An access bypass vulnerability in Drupal TFA Basic Plugins allows users with the administer users permission to view or generate recovery codes for other users. This issue affects TFA Basic Plugins: from 7.x-1.0 through 7.x-1.2.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Tfa Basic Plugins Project ≫ Tfa Basic Plugins SwPlatformdrupal Version >= 7.x-1.0 < 7.x-1.3
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.32% | 0.236 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 3.8 | 1.2 | 2.5 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N
|
| mlhess@drupal.org | 5.1 | 0 | 0 |
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
CWE-267 Privilege Defined With Unsafe Actions
A particular privilege, role, capability, or right can be used to perform unsafe actions that were not intended, even when it is assigned to the correct entity.
https://www.herodevs.com/vulnerability-directory/cve-2026-6816
https://d7es.tag1.com/security-advisories/tfa-basic-plugins-less-critical-access-bypass-sa-contrib-2025-085
https://www.herodevs.com/vulnerability-directory/cve-2026-6816?nes-for-drupal-7