{"id":"CVE-2026-4208","summary":"Authentication Bypass in extension \"E-Mail MFA Provider\" (mfa_email)","details":"The extension fails to properly reset the generated MFA code after successful authentication. This leads to a possible MFA bypass for future login attempts by providing an empty string as MFA code to the extensions MFA provider.","aliases":["GHSA-29r8-gvx4-r9w3"],"modified":"2026-08-12T03:51:43.044464912Z","published":"2026-03-17T08:34:52.141Z","database_specific":{"cna_assigner":"TYPO3","cwe_ids":["CWE-639"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/4xxx/CVE-2026-4208.json"},"references":[{"type":"WEB","url":"https://packagist.org"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/4xxx/CVE-2026-4208.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-4208"},{"type":"ADVISORY","url":"https://typo3.org/security/advisory/typo3-ext-sa-2026-007"},{"type":"PACKAGE","url":"https://github.com/MrSilaz/mfa_email"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/mrsilaz/mfa_email","events":[{"introduced":"0"},{"fixed":"3b0184c6e1ffb0fc652aa70321866fc93c28ba35"},{"introduced":"826a941c9206fde8b82146e9f8624f9ab12e0dce"},{"last_affected":"826a941c9206fde8b82146e9f8624f9ab12e0dce"}],"database_specific":{"cpe":["cpe:2.3:a:mrsilaz:mfa_mail:*:*:*:*:*:typo3:*:*","cpe:2.3:a:mrsilaz:mfa_mail:2.0.0:*:*:*:*:typo3:*:*"],"extracted_events":[{"introduced":"0"},{"fixed":"1.0.7"},{"introduced":"2.0.0"},{"last_affected":"2.0.0"}],"source":["CPE_RANGE","CPE_STRING"]}}],"versions":["2.0.0","v1.0.5","v2.0.0","v1.0.4","v1.0.3","v1.0.2","v1.0.1","v1.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-4208.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}