Junglewise Threat Intelligence

CVE-2024-27928: vantage6 two-factor authentication bypass via email reset

CVE-2024-27928 · Severity: medium · CVSS 4 · Published 2026-06-17

Technologies: vantage6 (PyPI). Vendors: PyPI.

Executive brief

vantage6 is an open-source platform used for privacy-preserving data analysis. A security flaw allows an attacker who has gained access to a user's email account to bypass two-factor authentication (2FA) by resetting both the account password and the 2FA token via email. This effectively reduces the security of the platform to a single factor, potentially allowing unauthorized access to sensitive research data if the user's email is compromised.

Technical details

A vulnerability in vantage6 prior to version 5.0.0 allows for the circumvention of multi-factor authentication (MFA). The application's recovery logic permits resetting both the user password and the 2FA token through email-based workflows. If an attacker compromises a user's email account, they can perform these resets sequentially to gain full access to the vantage6 account, effectively reducing the authentication mechanism to a single factor (CWE-308). This issue is addressed in version 5.0.0 by changing how 2FA tokens are managed or reset. No workarounds are available other than upgrading.

Affected products

  • vantage6 vantage6 < 5.0.0

Timeline

  • 2026-06-05: advisory: GitHub Security Advisory GHSA-4c5c-2vc3-x5w2 published
  • 2026-06-17: disclosed: CVE-2024-27928 published to NVD
  • 2026-06-17: patched: Version 5.0.0 released to fix the issue

References

Related threats