Intel

AIKIDO-2025-10561

drupal/alogin is vulnerable to Authentication Bypass Using an Alternate Path or Channel

Authentication Bypass Using an Alternate Path or ChannelCVE-2025-8995 Published Aug 18, 2025

98

Critical Risk

This Affects:

PHPdrupal/alogin
0.0.0 - 2.1.4
Fixed in 2.1.5
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to a Highly Critical Authentication Bypass vulnerability, where insufficient validation in AJAX callback handlers allows attackers to log in as any known user account without valid credentials. By sending a carefully crafted series of requests (as few as five by default) to trigger specific unvalidated authentication conditions, an attacker can completely bypass two-factor authentication protections. While the required request sequence might alert vigilant site monitors, the low threshold of requests, combined with predictable usernames, enables practical exploitation with a minimal forensic footprint.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

drupal/alogin is vulnerable to Authentication Bypass Using an Alternate Path or Channel in versions 0.0.0 - 2.1.4.

How to fix this

Upgrade the drupal/alogin library to the patch version.