Project machine name: 
auth_login_plus
Date: 
2026-October-07
Vulnerability: 
Improper authentication
Affected versions: 
<1.0.1
CVE IDs: 
CVE-2026-107261
Description: 

This module provides TOTP-based two-factor authentication (2FA) for Drupal, with an optional setting to enforce 2FA for all users site-wide.

The module may allow a user log in with only a password even when site-wide enforcement of 2FA is turned on.

Solution: 

Install the latest version:

After upgrading, users who previously disabled 2FA will be asked to set it up again at their next login. Administrators can also re-enable 2FA for a user from the admin overview so the user keeps their existing authenticator.

Fixed By: 
Coordinated By: