{"id":"CVE-2026-30777","details":"EC-CUBE provided by EC-CUBE CO.,LTD. contains a multi-factor authentication (MFA) bypass vulnerability. An attacker who has obtained a valid administrator ID and password may be able to bypass two-factor authentication and gain unauthorized access to the administrative page.","modified":"2026-08-12T03:51:35.352942874Z","published":"2026-03-05T05:31:35.025Z","database_specific":{"cna_assigner":"jpcert","cwe_ids":["CWE-288"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/30xxx/CVE-2026-30777.json","unresolved_ranges":[{"extracted_events":[{"introduced":"prior to 4.1.2-p5"},{"last_affected":"prior to 4.1.2-p5"},{"introduced":"prior to 4.2.3-p2"},{"last_affected":"prior to 4.2.3-p2"},{"introduced":"prior to 4.3.1-p1"},{"last_affected":"prior to 4.3.1-p1"}],"source":"AFFECTED_FIELD"}]},"references":[{"type":"WEB","url":"https://jvn.jp/en/jp/JVN63765888/"},{"type":"WEB","url":"https://www.ec-cube.net/info/weakness/20260209/index.php"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/30xxx/CVE-2026-30777.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-30777"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/ec-cube/ec-cube","events":[{"introduced":"5d02dde61f824fb9e264d003f59afc4663811567"},{"fixed":"710b64ce96786770fe59ba8255ff16925171f172"},{"introduced":"0fbb7b3a340c75f2860123d5e01d706f8a15127b"},{"fixed":"daed16e5da3c6847b232af24b06d76d55d8cbd42"},{"introduced":"c97204439000a877566bc232cb768862d3bfcbb0"},{"fixed":"cd8fa9826ddee6757bd2e952c9db4023e856c156"},{"introduced":"710b64ce96786770fe59ba8255ff16925171f172"},{"last_affected":"cd8fa9826ddee6757bd2e952c9db4023e856c156"}],"database_specific":{"source":["CPE_RANGE","CPE_STRING"],"cpe":["cpe:2.3:a:ec-cube:ec-cube:*:-:*:*:*:*:*:*","cpe:2.3:a:ec-cube:ec-cube:4.1.2:-:*:*:*:*:*:*","cpe:2.3:a:ec-cube:ec-cube:4.1.2:p1:*:*:*:*:*:*","cpe:2.3:a:ec-cube:ec-cube:4.1.2:p2:*:*:*:*:*:*","cpe:2.3:a:ec-cube:ec-cube:4.1.2:p3:*:*:*:*:*:*","cpe:2.3:a:ec-cube:ec-cube:4.1.2:p4:*:*:*:*:*:*","cpe:2.3:a:ec-cube:ec-cube:4.2.3:-:*:*:*:*:*:*","cpe:2.3:a:ec-cube:ec-cube:4.2.3:p1:*:*:*:*:*:*","cpe:2.3:a:ec-cube:ec-cube:4.3.1:-:*:*:*:*:*:*"],"extracted_events":[{"introduced":"4.1.0"},{"fixed":"4.1.2"},{"introduced":"4.2.0"},{"fixed":"4.2.3"},{"introduced":"4.3.0"},{"fixed":"4.3.1"},{"introduced":"4.1.2-NA"},{"last_affected":"4.1.2-NA"},{"introduced":"4.1.2-p1"},{"last_affected":"4.1.2-p1"},{"introduced":"4.1.2-p2"},{"last_affected":"4.1.2-p2"},{"introduced":"4.1.2-p3"},{"last_affected":"4.1.2-p3"},{"introduced":"4.1.2-p4"},{"last_affected":"4.1.2-p4"},{"introduced":"4.2.3-NA"},{"last_affected":"4.2.3-NA"},{"introduced":"4.2.3-p1"},{"last_affected":"4.2.3-p1"},{"introduced":"4.3.1-NA"},{"last_affected":"4.3.1-NA"}]}}],"versions":["4.1.2-NA","4.1.2-p1","4.1.2-p2","4.1.2-p3","4.1.2-p4","4.2.3-NA","4.2.3-p1","4.3.1-NA","4.3.1","4.3.0","co/4.2-20231026","4.2.3-20231023","co/4.2-20231005","4.2.3-20231002","co/4.2-20230921","4.2.2-20230616","4.2.2","co/4.2-20230608","4.2.2-20230606","co/4.2-20230511","4.2.1","co/4.2-20230222","co/4.2-20230216","4.2.0","co/4.2-20230119","4.2.1-20230116","co/4.2-20221215","co/4.2-20221027","co/4.2-20221020","co/4.2-20221013","co/4.2-20221006","co/4.1-20220210","4.1.2-20220128","4.1.2-20220203","co/4.1-20211202","4.1.1-20211130","4.1.1","co/4.1-20211125","co/4.1-20211118","co/4.1-20211111","4.1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-30777.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"}]}