CVE-2026-30777Disclosure(ec-cube / ec-cube)

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

EC-CUBE provided by EC-CUBE CO.,LTD. contains a multi-factor authentication (MFA) bypass vulnerability. An attacker who has obtained a valid administrator ID and password may be able to bypass two-factor authentication and gain unauthorized access to the administrative page.

0.0/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-288

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ec-cube

Threat summary

  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 1 mentions (2026-03-05); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
ec-cube

3 versions affected across 1 product

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-03-05: 1Mentions · 2026-03-08: 1Mentions · 2026-03-09: 1Technical Details · 2026-03-05: 1Technical Details · 2026-03-08: 1Technical Details · 2026-03-09: 103-0503-0803-09
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • 日本サイバーセキュリティ株式会社@jp_cb_security
    Disclosure

    EC-CUBEに多要素認証を回避できる脆弱性(CVE-2026-30777)が発覚しました。 EC-CUBEに多要素認証を回避できる脆弱性が発覚、ECサイト担当者が今すぐ確認すべきこと - サイバーセキュリティナビ https://blog.cbsec.jp/entry/2026/03/10/060000

    Post summary

    The post announces the discovery of CVE‑2026‑30777, which enables MFA bypass in EC‑CUBE, but provides no further details on exploitation, remediation, or PoC.

    0000055
    8 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-30777 EC-CUBE provided by EC-CUBE CO.,LTD. contains a multi-factor authentication (MFA) bypass vulnerability. An attacker who has obtained a valid administrator ID and pass… https://www.cve.org/CVERecord?id=CVE-2026-30777

    Post summary

    The post announces CVE‑2026‑30777, noting an MFA bypass in EC‑CUBE that permits administrators to bypass two‑factor authentication, but provides no PoC, tool, or patch details.

    00000233
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-30777 EC-CUBE Multi-Factor Authentication Bypass Vulnerability in Administrative Access https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-30777

    Post summary

    The statement announces CVE-2026-30777, a multi‑factor authentication bypass affecting EC‑CUBE administrative access, but provides no PoC, exploit code, or patch information.

    0000037
    4.0K followersView on X
CPE platform detail9 entries

9 of 9 entries

PartVendorProductVersionTarget SWTarget HW
Appec-cubeec-cube---
Appec-cubeec-cube4.1.2--
Appec-cubeec-cube4.1.2--
Appec-cubeec-cube4.1.2--
Appec-cubeec-cube4.1.2--
Appec-cubeec-cube4.1.2--
Appec-cubeec-cube4.2.3--
Appec-cubeec-cube4.2.3--
Appec-cubeec-cube4.3.1--

Explore more