CVE-2025-7030: Two-Factor Authentication Project Two-Factor Authentication
Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.
Privilege Defined With Unsafe Actions vulnerability in Drupal Two-factor Authentication (TFA) allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Two-factor Authentication (TFA): from 0.0.0 before 1.11.0.
Affected products
- Two-Factor Authentication Project Two-Factor Authentication: before 8.x-1.11 (fixed in 8.x-1.11)
Published 2025-07-08. Last modified 2026-06-17.