Description
Vulnerability in Drupal Email Login OTP. This issue affects Email Login OTP versions: *.*.
Published: 2026-08-25
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability found in Drupal Email Login OTP potentially allows an attacker to bypass the one‑time password authentication, granting unauthorized access to user accounts. This flaw arises from the module’s improper handling of the OTP verification process, which may enable credential replay or acceptance of forged OTPs, thereby compromising account confidentiality and integrity. The explicit technical details of the flaw are not fully disclosed in the public advisory, but the impact described strongly suggests that compromised credentials could lead to elevated privileges or full site takeover if exploited.

Affected Systems

Drupal Email Login OTP is the affected product under the Drupal environment. No specific version range is listed; the advisory indicates that all versions represented by "*.*" are vulnerable. Administrators should treat any installation of the Email Login OTP module as potentially impacted.

Risk and Exploitability

The CVSS score is not publicly available, and EPSS is listed as not available, leaving a formal risk quantification absent. The vulnerability is not yet included in the CISA KEV catalog, which suggests there are no confirmed exploitation reports. The attack vector cannot be definitively determined from the published data; it is likely remote but remains speculative. Based on the severity implied by the potential for authentication bypass, the risk remains unquantified but appears significant enough to merit urgency, pending vendor remediation. Attackers would need to exploit the flawed OTP logic, possibly through guess or replay, to gain unauthorized access.

Generated by OpenCVE AI on August 26, 2026 at 01:16 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check the Drupal project website for an official fix or advisory update for the Email Login OTP module.
  • Apply any available patch or version upgrade that addresses the authentication bypass flaw as soon as it is released.
  • If a patch is not yet available, consider disabling the Email Login OTP feature or requiring additional MFA layers before user login to reduce the attack surface.

Generated by OpenCVE AI on August 26, 2026 at 01:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Wed, 26 Aug 2026 01:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269

Tue, 25 Aug 2026 22:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in Drupal Email Login OTP. This issue affects Email Login OTP versions: *.*.
Title Email Login OTP - Critical - Unsupported - SA-CONTRIB-2026-085
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: drupal

Published:

Updated: 2026-08-25T22:21:59.242Z

Reserved: 2026-07-22T17:06:44.287Z

Link: CVE-2026-16642

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-25T23:16:56.997

Modified: 2026-08-25T23:16:56.997

Link: CVE-2026-16642

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T01:30:16Z

Weaknesses
  • CWE-269

    Improper Privilege Management