Description
Vulnerability in Drupal Email Login OTP. This issue affects Email Login OTP versions: *.*.
Published: 2026-08-25
Score: 5.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Authentication Bypass
Action: Apply Patch
AI Analysis

Impact

The Drupal module Email Login OTP contains an input validation flaw (CWE‑20) that allows an attacker to supply forged or replayed one‑time passwords, effectively bypassing the authentication process. Based on the description, it is inferred that once the OTP is incorrectly verified, an attacker can log in as the target user and gain all privileges associated with that account. The flaw therefore threatens account confidentiality and integrity and could lead to full site takeover if an attacker can compromise privileged accounts.

Affected Systems

Drupal Email Login OTP, the module used within the Drupal CMS, is affected. No specific version range is listed because the advisory lists versions as "*.*", indicating that every released version of the module is potentially vulnerable. Administrators should examine any installation of this module regardless of its numeric version.

Risk and Exploitability

The CVSS score of 5.7 indicates moderate severity, and the EPSS score of < 1% suggests a low probability of exploitation. The vulnerability is not in the CISA KEV catalog, implying no documented operational exploitation. Attackers would likely target the OTP verification endpoint, which is remotely accessible over the Internet, but the exact attack vector is not detailed in the advisory. The combination of a moderate score, low exploitation likelihood, and absence of KEV entries means the risk remains moderate and should be addressed before exploitation occurs.

Generated by OpenCVE AI on August 27, 2026 at 00:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Email Login OTP module to a version that addresses the input‑validation flaw (CWE‑20) or apply any vendor‑supplied patch.
  • If no patch exists, disable the module entirely or replace it with a trusted authentication method until remediation is available.
  • Configure rate limiting or request‑throttling for OTP verification to mitigate replay or brute‑force attempts.

Generated by OpenCVE AI on August 27, 2026 at 00:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Fri, 28 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Drupal
Drupal email Login Otp
Vendors & Products Drupal
Drupal email Login Otp

Wed, 26 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269

Wed, 26 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
Metrics cvssV3_1

{'score': 5.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 01:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269

Tue, 25 Aug 2026 22:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in Drupal Email Login OTP. This issue affects Email Login OTP versions: *.*.
Title Email Login OTP - Critical - Unsupported - SA-CONTRIB-2026-085
References

Subscriptions

Drupal Email Login Otp
cve-icon MITRE

Status: PUBLISHED

Assigner: drupal

Published:

Updated: 2026-08-26T18:55:46.788Z

Reserved: 2026-07-22T17:06:44.287Z

Link: CVE-2026-16642

cve-icon Vulnrichment

Updated: 2026-08-26T18:55:37.824Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-25T23:16:56.997

Modified: 2026-08-28T15:29:44.967

Link: CVE-2026-16642

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T20:34:08Z

Weaknesses
  • CWE-20

    Improper Input Validation