Shodan
Maps
Images
Monitor
Developer
More...
Dashboard
View Api Docs
Vulnerabilities
By Date
Known Exploited
Advanced Search
Vulnerable Software
Vendors
Products
Vulnerability Details CVE-2026-6816
An access bypass vulnerability in Drupal TFA Basic Plugins allows users with the administer users permission to view or generate recovery codes for other users. This issue affects TFA Basic Plugins: from 7.x-1.0 through 7.x-1.2.
Exploit prediction scoring system (EPSS) score
EPSS Score
0.0
EPSS Ranking
8.8%
CVSS Severity
CVSS v3 Score
3.8
References
https://d7es.tag1.com/security-advisories/tfa-basic-plugins-less-critical-access-bypass-sa-contrib-2025-085
https://www.herodevs.com/vulnerability-directory/cve-2026-6816
https://www.herodevs.com/vulnerability-directory/cve-2026-6816?nes-for-drupal-7
Products affected by CVE-2026-6816
Tfa Basic Plugins Project
»
Tfa Basic Plugins
»
Version:
Any
cpe:2.3:a:tfa_basic_plugins_project:tfa_basic_plugins:*
Products
Monitor
Search Engine
Developer API
Maps
Bulk Data
Images
Snippets
Pricing
Membership
API Subscriptions
Enterprise
Contact Us
support@shodan.io
Shodan ® - All rights reserved