Vulnerability DRUPAL-CONTRIB-2026-201

Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
11 hours ago
October 07, 2026 at 04:23 PM UTC
No summary available

Details

This module provides TOTP-based two-factor authentication (2FA) for Drupal, with an optional setting to enforce 2FA for all users site-wide.

The module may allow a user log in with only a password even when site-wide enforcement of 2FA is turned on.

Impacted packages

Timeline

Published
11 hours ago
October 07, 2026 at 04:23 PM UTC
Last Modified
7 hours ago
October 07, 2026 at 08:15 PM UTC