An access bypass vulnerability in Drupal TFA Basic Plugins allows users with the administer users permission to view or generate recovery codes for other users.
This issue affects TFA Basic Plugins: from 7.x-1.0 through 7.x-1.2.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/6xxx/CVE-2026-6816.json",
"cwe_ids": [
"CWE-267"
],
"cna_assigner": "drupal"
}{
"source": "AFFECTED_FIELD",
"extracted_events": [
{
"introduced": "7.x-1.0"
},
{
"last_affected": "7.x-1.2"
}
]
}