Project machine name: 
auth_login_plus
Date: 
2026-October-07
Vulnerability: 
Improper authentication
Affected versions: 
<1.0.1
CVE IDs: 
CVE-2026-107254
Description: 

This module provides TOTP-based two-factor authentication (2FA) for Drupal.

The module doesn't enforce the second factor when a user logs in with Drupal core's one-time login link.

This vulnerability is mitigated by the fact that an attacker must have access to a valid one-time login link for a victim's account.

Solution: 

Install the latest version:

After upgrading, users with 2FA enabled will be asked for their verification code after using a one-time login link.

Fixed By: 
Coordinated By: