CVE-2026-6816 PUBLISHED

TFA Basic Plugins - Access Bypass

Assigner: drupal
Reserved: 21.04.2026 Published: 28.05.2026 Updated: 28.05.2026

An access bypass vulnerability in Drupal TFA Basic Plugins allows users with the administer users permission to view or generate recovery codes for other users.

This issue affects TFA Basic Plugins: from 7.x-1.0 through 7.x-1.2.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
CVSS Score: 5.1

Product Status

Vendor Drupal
Product TFA Basic Plugins
Versions Default: unknown
  • affected from 7.x-1.0 to 7.x-1.2 (incl.)

References

Problem Types

  • CWE-267 Privilege Defined With Unsafe Actions CWE

Impacts

  • CAPEC-180 Exploiting Incorrectly Configured Access Control Security Levels