CVE-2026-30777: Ec-Cube

Medium severity, CVSS 6.5. EPSS: 0.6% chance of exploitation in the next 30 days.

EC-CUBE provided by EC-CUBE CO.,LTD. contains a multi-factor authentication (MFA) bypass vulnerability. An attacker who has obtained a valid administrator ID and password may be able to bypass two-factor authentication and gain unauthorized access to the administrative page.

Affected products

  • Ec-Cube Ec-Cube: from 4.1.0, before 4.1.2 (fixed in 4.1.2); from 4.2.0, before 4.2.3 (fixed in 4.2.3); from 4.3.0, before 4.3.1 (fixed in 4.3.1); version 4.1.2 only; version 4.2.3 only; version 4.3.1 only

Published 2026-03-05. Last modified 2026-06-17.