CVE-2026-4208 - Authentication Bypass in extension "E-Mail MFA Provider" (mfa_email)
CVE ID :CVE-2026-4208
Published : March 17, 2026, 9:16 a.m. | 3 hours, 14 minutes ago
Description :The extension fails to properly reset the generated MFA code after successful authentication. This leads to a possible MFA bypass for future login attempts by providing an empty string as MFA code to the extensions MFA provider.
Severity: 7.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : March 17, 2026, 9:16 a.m. | 3 hours, 14 minutes ago
Description :The extension fails to properly reset the generated MFA code after successful authentication. This leads to a possible MFA bypass for future login attempts by providing an empty string as MFA code to the extensions MFA provider.
Severity: 7.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...