CVE-2026-4208
EUVD-2026-1255417.03.2026, 09:16
The extension fails to properly reset the generated MFA code after successful authentication. This leads to a possible MFA bypass for future login attempts by providing an empty string as MFA code to the extensions MFA provider.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| mrsilaz | mfa_mail | 𝑥 < 1.0.7 |
| mrsilaz | mfa_mail | 2.0.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration