CVE-2025-7030: Two-Factor Authentication Project Two-Factor Authentication

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

Privilege Defined With Unsafe Actions vulnerability in Drupal Two-factor Authentication (TFA) allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Two-factor Authentication (TFA): from 0.0.0 before 1.11.0.

Affected products

Published 2025-07-08. Last modified 2026-06-17.