CVE-2026-30777

EUVD-2026-9791
EC-CUBE provided by EC-CUBE CO.,LTD. contains a multi-factor authentication (MFA) bypass vulnerability. An attacker who has obtained a valid administrator ID and password may be able to bypass two-factor authentication and gain unauthorized access to the administrative page.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.5 MEDIUM
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
ec-cubeec-cube
4.1.0 ≤
𝑥
< 4.1.2
ec-cubeec-cube
4.2.0 ≤
𝑥
< 4.2.3
ec-cubeec-cube
4.3.0 ≤
𝑥
< 4.3.1
ec-cubeec-cube
4.1.2
ec-cubeec-cube
4.1.2:p1
ec-cubeec-cube
4.1.2:p2
ec-cubeec-cube
4.1.2:p3
ec-cubeec-cube
4.1.2:p4
ec-cubeec-cube
4.2.3
ec-cubeec-cube
4.2.3:p1
ec-cubeec-cube
4.3.1
𝑥
= Vulnerable software versions