Medium severity6.5NVD Advisory· Published Mar 5, 2026· Updated Jun 17, 2026
CVE-2026-30777
CVE-2026-30777
Description
EC-CUBE provided by EC-CUBE CO.,LTD. contains a multi-factor authentication (MFA) bypass vulnerability. An attacker who has obtained a valid administrator ID and password may be able to bypass two-factor authentication and gain unauthorized access to the administrative page.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
12cpe:2.3:a:ec-cube:ec-cube:*:-:*:*:*:*:*:*+ 9 more
- cpe:2.3:a:ec-cube:ec-cube:*:-:*:*:*:*:*:*range: >=4.1.0,<4.1.2
- cpe:2.3:a:ec-cube:ec-cube:4.1.2:-:*:*:*:*:*:*
- cpe:2.3:a:ec-cube:ec-cube:4.1.2:p1:*:*:*:*:*:*
- cpe:2.3:a:ec-cube:ec-cube:4.1.2:p2:*:*:*:*:*:*
- cpe:2.3:a:ec-cube:ec-cube:4.1.2:p3:*:*:*:*:*:*
- cpe:2.3:a:ec-cube:ec-cube:4.1.2:p4:*:*:*:*:*:*
- cpe:2.3:a:ec-cube:ec-cube:4.2.3:-:*:*:*:*:*:*
- cpe:2.3:a:ec-cube:ec-cube:4.2.3:p1:*:*:*:*:*:*
- cpe:2.3:a:ec-cube:ec-cube:4.3.1:-:*:*:*:*:*:*
- (no CPE)
prior to 4.1.2-p5+ 1 more
- (no CPE)range: prior to 4.1.2-p5
- (no CPE)range: prior to 4.3.1-p1
Patches
Vulnerability mechanics
References
2- www.ec-cube.net/info/weakness/20260209/index.phpnvdPatchVendor Advisory
- jvn.jp/en/jp/JVN63765888/nvdThird Party Advisory
News mentions
0No linked articles in our index yet.