Unrated severityNVD Advisory· Published Mar 5, 2026· Updated Mar 6, 2026
CVE-2026-30777
CVE-2026-30777
Description
EC-CUBE provided by EC-CUBE CO.,LTD. contains a multi-factor authentication (MFA) bypass vulnerability. An attacker who has obtained a valid administrator ID and password may be able to bypass two-factor authentication and gain unauthorized access to the administrative page.
Affected products
3- Range: prior to 4.3.1-p1
- EC-CUBE CO.,LTD./EC-CUBE 4.1 seriesv5Range: prior to 4.1.2-p5
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.