CVE Vulnerabilities

CVE-2025-12760

Authentication Bypass Using an Alternate Path or Channel

Published: Nov 18, 2025 | Modified: Dec 08, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Email TFA allows Functionality Bypass.This issue affects Email TFA: from 0.0.0 before 2.0.6.

Weakness

The product requires authentication, but the product has an alternate path or channel that does not require authentication.

Affected Software

Name Vendor Start Version End Version
Email_tfa Email_tfa_project * 2.0.6 (excluding)

Potential Mitigations

References