CVE Vulnerabilities

CVE-2025-12466

Authentication Bypass Using an Alternate Path or Channel

Published: Oct 30, 2025 | Modified: Dec 04, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Simple OAuth (OAuth2) & OpenID Connect allows Authentication Bypass.This issue affects Simple OAuth (OAuth2) & OpenID Connect: from 6.0.0 before 6.0.7.

Weakness

The product requires authentication, but the product has an alternate path or channel that does not require authentication.

Affected Software

Name Vendor Start Version End Version
Simple_oauth Simple_oauth_project 6.0.0 (including) 6.0.7 (excluding)

Potential Mitigations

References