An access bypass vulnerability in Drupal TFA Basic Plugins allows users with the administer users permission to view or generate recovery codes for other users.
This issue affects TFA Basic Plugins: from 7.x-1.0 through 7.x-1.2.
References
| Link | Resource |
|---|---|
| https://d7es.tag1.com/security-advisories/tfa-basic-plugins-less-critical-access-bypass-sa-contrib-2025-085 | Third Party Advisory |
| https://www.herodevs.com/vulnerability-directory/cve-2026-6816 | Exploit Third Party Advisory |
| https://www.herodevs.com/vulnerability-directory/cve-2026-6816?nes-for-drupal-7 | Exploit Third Party Advisory |
Configurations
History
01 Jun 2026, 17:15
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://d7es.tag1.com/security-advisories/tfa-basic-plugins-less-critical-access-bypass-sa-contrib-2025-085 - Third Party Advisory | |
| References | () https://www.herodevs.com/vulnerability-directory/cve-2026-6816 - Exploit, Third Party Advisory | |
| References | () https://www.herodevs.com/vulnerability-directory/cve-2026-6816?nes-for-drupal-7 - Exploit, Third Party Advisory | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 3.8 |
| CPE | cpe:2.3:a:tfa_basic_plugins_project:tfa_basic_plugins:*:*:*:*:*:drupal:*:* | |
| First Time |
Tfa Basic Plugins Project tfa Basic Plugins
Tfa Basic Plugins Project |
29 May 2026, 20:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
28 May 2026, 23:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-28 23:16
Updated : 2026-06-01 17:15
NVD link : CVE-2026-6816
Mitre link : CVE-2026-6816
CVE.ORG link : CVE-2026-6816
JSON object : View
Products Affected
tfa_basic_plugins_project
- tfa_basic_plugins
CWE
CWE-267
Privilege Defined With Unsafe Actions
