CVE-2026-4208Disclosure(mrsilaz / mfa_mail)

LOWCVSS 8.8 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The extension fails to properly reset the generated MFA code after successful authentication. This leads to a possible MFA bypass for future login attempts by providing an empty string as MFA code to the extensions MFA provider.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-639

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • mfa_mail

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
mfa_mail

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-03-17: 3Technical Details · 2026-03-17: 203-17
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-4208 Multi-Factor Authentication Bypass in Extension via Empty String Code Injection https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-4208

    Post summary

    CVE-2026-4208 is a newly disclosed vulnerability that allows an MFA bypass through empty string code injection, but no PoC, exploit, or patch information is provided.

    0001060
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4208 The extension fails to properly reset the generated MFA code after successful authentication. This leads to a possible MFA bypass for future login attempts by providing… https://www.cve.org/CVERecord?id=CVE-2026-4208

    Post summary

    The post discloses CVE‑2026‑4208, explaining that the extension fails to reset the MFA code after authentication, enabling a potential MFA bypass. No PoC, exploit tool, patch, or active exploitation is mentioned.

    00000141
    56.8K followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-4208 📊 Severity: 7.7 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-4208 #CVE-2026-4208 #CVE #High  #CyberSecurity #InfoSec https://t.co/ypLV9RIOkI

    Post summary

    The tweet merely announces the existence of CVE-2026-4208 with a severity score of 7.7, providing no additional technical details, exploit code, or mitigation information.

    0000046
    101 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appmrsilazmfa_mail-typo3-
Appmrsilazmfa_mail2.0.0typo3-

Explore more