PT-2025-33500 · Drupal · Drupal Authenticator Login

·

CVE-2025-8995

·

Published

2025-08-13

·

Updated

2025-08-21

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Drupal Authenticator Login versions 0.0.0 through 2.1.3
Description: An Authentication Bypass Using an Alternate Path or Channel issue exists in Drupal Authenticator Login, allowing for Authentication Bypass.
Recommendations: Update to version 2.1.4 or later.

Exploit

Fix

Missing Authentication

Authentication Bypass Using an Alternate Path or Channel

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-8995
DRUPAL-CONTRIB-2025-096

Affected Products

Drupal Authenticator Login