CVE-2026-6816

Source
https://cve.org/CVERecord?id=CVE-2026-6816
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-6816.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-6816
Published
2026-05-28T22:50:49.419Z
Modified
2026-07-23T03:56:36.965017521Z
Severity
  • 5.1 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
TFA Basic Plugins - Access Bypass
Details

An access bypass vulnerability in Drupal TFA Basic Plugins allows users with the administer users permission to view or generate recovery codes for other users.

This issue affects TFA Basic Plugins: from 7.x-1.0 through 7.x-1.2.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/6xxx/CVE-2026-6816.json",
    "cwe_ids": [
        "CWE-267"
    ],
    "cna_assigner": "drupal"
}
References

Affected packages

Git / git.drupalcode.org/project/tfa_basic

Affected ranges

Type
GIT
Repo
https://git.drupalcode.org/project/tfa_basic
Events
Introduced
ab4e3246272fd5c37dd63752addf570cf8d48bee
Last affected
3fa7576c32e5d6fe4f3a5ac417b27fc6f9587209
Database specific
{
    "source": "AFFECTED_FIELD",
    "extracted_events": [
        {
            "introduced": "7.x-1.0"
        },
        {
            "last_affected": "7.x-1.2"
        }
    ]
}

Affected versions

7.*
7.x-1.0
7.x-1.1
7.x-1.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-6816.json"