PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-107268 drupal CVE debrief

The Two Factor Authentication - TFA / Passwordless Login module for Drupal contains a vulnerability in the headless login endpoint that can disclose the site's stored miniOrange customer API key to unauthenticated users. The vulnerability is mitigated by the fact that Headless 2FA must be turned on by a user with a `miniorange 2fa headless` permission, which is a restricted permission.

Vendor
drupal
Product
miniorange_2fa
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-07
Original CVE updated
2026-10-07
Advisory published
2026-10-07
Advisory updated
2026-10-07

Who should care

Drupal site administrators and security teams should assess the exposure of their systems to this vulnerability, especially those using the affected module versions. They should verify if the Two Factor Authentication - TFA / Passwordless Login module is installed and enabled, check for potential exposure of the miniOrange customer API key, and prioritize remediation efforts accordingly. Additionally, security teams should review system logs and monitor 2F

Why it matters

The Two Factor Authentication - TFA / Passwordless Login module for Drupal vulnerability allows disclosure of sensitive information to unauthenticated users. Defenders should prioritize verifying exposure, assessing impact, and remediating affected systems.

  • Disclosure of sensitive information (miniOrange customer API key) to unauthenticated users.
  • Potential unauthorized access to sensitive information.
  • Need for verification of exposure and impact on systems.
  • Prioritization of remediation efforts for affected systems.

Technical summary

The vulnerability exists in the headless login endpoint of the Two Factor Authentication - TFA / Passwordless Login module for Drupal. An unauthenticated user can exploit this vulnerability to disclose the site's stored miniOrange customer API key. The vulnerability is mitigated by the fact that Headless 2FA must be turned on by a user with a `miniorange 2fa headless` permission, which is a restricted permission.

Defensive priority

Defenders should prioritize verifying exposure and assessing the impact of this vulnerability on their systems, especially those using the affected module versions.

Recommended defensive actions

  • Verify if the Two Factor Authentication - TFA / Passwordless Login module is installed and enabled on your Drupal site.
  • Check if the site's stored miniOrange customer API key is exposed to unauthenticated users.
  • Assess the impact of the vulnerability on your system and prioritize remediation.
  • Update the module to a fixed version (5.4.1 or 5.5.2) as soon as possible.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.

Evidence notes

The vulnerability is confirmed to exist in the Two Factor Authentication - TFA / Passwordless Login module for Drupal, with versions <5.4.1 and >=5.5.0 <5.5.2 being affected. The disclosure of the miniOrange customer API key to unauthenticated users is a significant concern. Defenders should verify exposure, assess impact, and remediate affected systems. Evidence is limited to public CVE details and source item information.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-107268 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-107268

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-107268 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107268

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • DRUPAL-CONTRIB-2026-207

    Unverified legacy reference

    URL: https://storage.googleapis.com/osv-vulnerabilities/Packagist/DRUPAL-CONTRIB-2026-207.json

    osv_dev

  • Source reference

    Unverified legacy reference

    URL: https://www.drupal.org/sa-contrib-2026-207

    Supplemental source

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.