CVE-2026-4208
Authentication Bypass in extension "E-Mail MFA Provider" (mfa_email)
Title source: cnaDescription
The extension fails to properly reset the generated MFA code after successful authentication. This leads to a possible MFA bypass for future login attempts by providing an empty string as MFA code to the extensions MFA provider.
References (1)
Scores
EPSS
0.0005
EPSS Percentile
16.9%
Details
CWE
CWE-639
Status
published
Products (2)
ralffreit/mfa-email
Packagist
TYPO3/Extension "E-Mail MFA Provider"
< 2.0.0
Published
Mar 17, 2026
Tracked Since
Mar 17, 2026