CVE-2026-4208

Authentication Bypass in extension "E-Mail MFA Provider" (mfa_email)

Title source: cna

Description

The extension fails to properly reset the generated MFA code after successful authentication. This leads to a possible MFA bypass for future login attempts by providing an empty string as MFA code to the extensions MFA provider.

Scores

EPSS 0.0005
EPSS Percentile 16.9%

Details

CWE
CWE-639
Status published
Products (2)
ralffreit/mfa-email Packagist
TYPO3/Extension "E-Mail MFA Provider" < 2.0.0
Published Mar 17, 2026
Tracked Since Mar 17, 2026