Date: 
2026-September-02
Vulnerability: 
Access Bypass
Affected versions: 
<2.4.0
CVE IDs: 
CVE-2026-84923
Description: 

This module enables you to add extra layer of verification for user registration.

The module doesn't sufficiently validate user-supplied input resulting in an account takeover vulnerability.

Solution: 

Install the latest version:

If you are using the OTP Verification module for Drupal, upgrade to latest version 8.x-2.4

Reported By: 
Coordinated By: