PatchSiren cyber security CVE debrief
CVE-2026-107268 drupal CVE debrief
The Two Factor Authentication - TFA / Passwordless Login module for Drupal contains a vulnerability in the headless login endpoint that can disclose the site's stored miniOrange customer API key to unauthenticated users. The vulnerability is mitigated by the fact that Headless 2FA must be turned on by a user with a `miniorange 2fa headless` permission, which is a restricted permission.
- Vendor
- drupal
- Product
- miniorange_2fa
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-07
- Original CVE updated
- 2026-10-07
- Advisory published
- 2026-10-07
- Advisory updated
- 2026-10-07
Who should care
Drupal site administrators and security teams should assess the exposure of their systems to this vulnerability, especially those using the affected module versions. They should verify if the Two Factor Authentication - TFA / Passwordless Login module is installed and enabled, check for potential exposure of the miniOrange customer API key, and prioritize remediation efforts accordingly. Additionally, security teams should review system logs and monitor 2F
Why it matters
The Two Factor Authentication - TFA / Passwordless Login module for Drupal vulnerability allows disclosure of sensitive information to unauthenticated users. Defenders should prioritize verifying exposure, assessing impact, and remediating affected systems.
- Disclosure of sensitive information (miniOrange customer API key) to unauthenticated users.
- Potential unauthorized access to sensitive information.
- Need for verification of exposure and impact on systems.
- Prioritization of remediation efforts for affected systems.
Technical summary
The vulnerability exists in the headless login endpoint of the Two Factor Authentication - TFA / Passwordless Login module for Drupal. An unauthenticated user can exploit this vulnerability to disclose the site's stored miniOrange customer API key. The vulnerability is mitigated by the fact that Headless 2FA must be turned on by a user with a `miniorange 2fa headless` permission, which is a restricted permission.
Defensive priority
Defenders should prioritize verifying exposure and assessing the impact of this vulnerability on their systems, especially those using the affected module versions.
Recommended defensive actions
- Verify if the Two Factor Authentication - TFA / Passwordless Login module is installed and enabled on your Drupal site.
- Check if the site's stored miniOrange customer API key is exposed to unauthenticated users.
- Assess the impact of the vulnerability on your system and prioritize remediation.
- Update the module to a fixed version (5.4.1 or 5.5.2) as soon as possible.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
The vulnerability is confirmed to exist in the Two Factor Authentication - TFA / Passwordless Login module for Drupal, with versions <5.4.1 and >=5.5.0 <5.5.2 being affected. The disclosure of the miniOrange customer API key to unauthenticated users is a significant concern. Defenders should verify exposure, assess impact, and remediate affected systems. Evidence is limited to public CVE details and source item information.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-107268 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-107268
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-107268 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107268
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
DRUPAL-CONTRIB-2026-207
Unverified legacy reference
URL: https://storage.googleapis.com/osv-vulnerabilities/Packagist/DRUPAL-CONTRIB-2026-207.json
osv_dev
-
Source reference
Unverified legacy reference
URL: https://www.drupal.org/sa-contrib-2026-207
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.