Junglewise Threat Intelligence

CVE-2026-16642: Drupal Email Login OTP brute force protection bypass

CVE-2026-16642 · Severity: medium · CVSS 5.7 · Published 2026-08-25

Vendors: Packagist:Https://Packages.Drupal.Org/8, Drupal.

Executive brief

The Email Login OTP module for Drupal provides two-factor authentication via email-based one-time passwords. The module contains a vulnerability that allows attackers to brute-force OTP codes without adequate rate limiting or account lockout protections. This could allow unauthorized account takeover by bypassing the 2FA mechanism intended to secure user access.

Technical details

The vulnerability is a lack of brute-force protection on the OTP verification form in the Email Login OTP Drupal module. Attackers can submit unlimited OTP verification attempts without rate limiting, account lockout, or progressive delays. The module is no longer maintained, and the security issue has been left unresolved by the maintainer. The vulnerability is network-accessible during the 2FA login flow (post-authentication). An attacker can exploit this by repeatedly guessing OTP codes to gain access to accounts that have 2FA enabled, circumventing the intended second factor of authentication.

Affected products

  • Drupal Email Login OTP all versions

Timeline

  • 2026-07-22: disclosed
  • 2026-08-25: advisory: CVE-2026-16642 assigned; module marked unsupported

References