CVE-2024-27928
vantage6 is an open-source infrastructure for privacy preserving analysis. Prior to version 5.0.0, if an attacker hacks into a vantage6 user's email account, they can 1) reset the password via email and then 2) reset the 2FA token via email. This way they reduce 2FA to 1FA (email access). Note that most email providers require 2FA to access email, so this issue is not very likely to cause issues. Version 5.0.0 fixes the issue. No known workarounds are available.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.9
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.28%
- CWE
- CWE-308
- Published
- 2026-06-17
- Last modified
- 2026-06-20
Affected products
- vantage6 vantage6
Weakness type
Related vulnerabilities
- CVE-2026-58240 — Missing Authentication check in SAP NetWeaver (Message Server)
- CVE-2026-85590 — phpMyFAQ before 4.1.8 Authentication Bypass via Two-Factor Disable
- CVE-2026-67611 — OpenEMR 8.2.0 OAuth2 Password Grant Authentication Bypass via SMART Configuration
- CVE-2026-56022 — Webmin MFA bypass
- CVE-2026-45749 — Termix's TOTP two-factor authentication can be disabled or bypassed using only the account password
- CVE-2026-33550 — SOGo before 5.12.5 does not renew the OTP if a user disables/enables it, and has a too short length...
- CVE-2025-64103 — Zitadel Bypass Second Authentication Factor
- CVE-2025-42959 — Missing Authentication check after implementation of SAP Security Note 3007182 and 3537476