Intel

AIKIDO-2025-10782

drupal/email_tfa is vulnerable to Access bypass

Access bypassCVE-2025-12760 Published Nov 10, 2025

50

Medium Risk

This Affects:

PHPdrupal/email_tfa
1.0.0 - 2.0.5
Fixed in 2.0.6
Are you affected? Scan for Free

TL;DR

The Email TFA module adds email-based two-factor authentication (2FA) to Drupal logins. In some cases, the module fails to fully enforce 2FA across all login methods, allowing users to bypass the additional authentication step. This vulnerability is mitigated by the fact that an attacker must already possess valid login credentials (username and password) to exploit it.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

drupal/email_tfa is vulnerable to Access bypass in versions 1.0.0 - 2.0.5.

How to fix this

Upgrade the drupal/email_tfa library to the patch version.