Description
Improper validation of specified type of input vulnerability in Magarsus Consulting Ltd. Co. IDM-MFA allows Authentication Bypass.

This issue affects IDM-MFA: from 2025.11.27 before 2026.03.10.
Published: 2026-07-22
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from improper validation of a specific type of input in Magarsus Consulting Ltd. Co.'s IDM‑MFA, corresponding to CWE‑1287, allowing an attacker to bypass the OTP authentication step and gain unauthorized access to protected resources. This authentication bypass directly undermines the confidentiality and integrity of systems relying on the product and can let any user assume privileged roles if they can exploit the input flaw.

Affected Systems

Affected systems are Magarsus Consulting Ltd. Co.'s IDM‑MFA product series, specifically versions released on or after November 27, 2025 and before March 10, 2026. The product name is IDM‑MFA and the vendor is Magarsus Consulting Ltd. Co.

Risk and Exploitability

The vulnerability’s CVSS score of 8.1 indicates high severity, but its EPSS score is less than 1%, suggesting a low probability of exploitation in the wild as of the current data. It is not listed in the CISA KEV catalog. The attack vector is not explicitly documented; based on the description it is inferred that the attacker might exploit the flaw by submitting crafted input during the OTP verification phase, potentially from a remote or local context. This flaw is classified as CWE‑1287, an input validation issue. The lack of a public patch or CNA workaround currently means the risk remains until an official fix is released.

Generated by OpenCVE AI on August 3, 2026 at 23:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Disable IDM‑MFA for critical accounts or replace it with an alternative MFA solution until a vendor fix that addresses the input validation flaw (CWE‑1287) is released.
  • Audit authentication logs for anomalous login patterns that may indicate an OTP bypass attempt.
  • Contact Magarsus Consulting for updates on the fix and schedule of release.

Generated by OpenCVE AI on August 3, 2026 at 23:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Magarsus Consulting
Magarsus Consulting idm-mfa
Vendors & Products Magarsus Consulting
Magarsus Consulting idm-mfa

Wed, 22 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 22 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Description Improper validation of specified type of input vulnerability in Magarsus Consulting Ltd. Co. IDM-MFA allows Authentication Bypass. This issue affects IDM-MFA: from 2025.11.27 before 2026.03.10.
Title OTP Bypass in Magarsus' IDM-MFA
Weaknesses CWE-1287
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N'}


Subscriptions

Magarsus Consulting Idm-mfa
cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-07-22T12:43:01.406Z

Reserved: 2026-03-24T13:41:44.976Z

Link: CVE-2026-4773

cve-icon Vulnrichment

Updated: 2026-07-22T12:42:58.395Z

cve-icon NVD

Status : Deferred

Published: 2026-07-22T12:18:12.587

Modified: 2026-07-22T16:21:53.517

Link: CVE-2026-4773

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T00:00:09Z

Weaknesses
  • CWE-1287

    Improper Validation of Specified Type of Input