Vulnerability DRUPAL-CONTRIB-2026-197
Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
11 hours ago
October 07, 2026 at 04:21 PM UTC
No summary available
Details
This module provides TOTP-based two-factor authentication (2FA) for Drupal.
The module doesn't enforce the second factor when a user logs in with Drupal core's one-time login link.
This vulnerability is mitigated by the fact that an attacker must have access to a valid one-time login link for a victim's account.
References
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Impacted packages
Timeline
Published
11 hours ago
October 07, 2026 at 04:21 PM UTC
Last Modified
7 hours ago
October 07, 2026 at 08:15 PM UTC