CVE-2026-4773

HIGH

OTP Bypass in Magarsus' IDM-MFA

Title source: cna
STIX 2.1

Description

Improper validation of specified type of input vulnerability in Magarsus Consulting Ltd. Co. IDM-MFA allows Authentication Bypass. This issue affects IDM-MFA: from 2025.11.27 before 2026.03.10.

References (1)

Core 1
Core References

Scores

CVSS v3 8.1
EPSS 0.0032
EPSS Percentile 24.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-1287
Status published
Products (1)
Magarsus Consulting Ltd. Co./IDM-MFA 2025.11.27 - 2026.03.10
Published Jul 22, 2026
Tracked Since Jul 22, 2026