Vulnerability Details CVE-2026-30777
EC-CUBE provided by EC-CUBE CO.,LTD. contains a multi-factor authentication (MFA) bypass vulnerability. An attacker who has obtained a valid administrator ID and password may be able to bypass two-factor authentication and gain unauthorized access to the administrative page.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 19.6%
CVSS Severity
CVSS v3 Score 4.9
Products affected by CVE-2026-30777
-
cpe:2.3:a:ec-cube:ec-cube:*
-
cpe:2.3:a:ec-cube:ec-cube:4.1.2
-
cpe:2.3:a:ec-cube:ec-cube:4.2.3
-
cpe:2.3:a:ec-cube:ec-cube:4.3.1