Vulnerability Description
EC-CUBE provided by EC-CUBE CO.,LTD. contains a multi-factor authentication (MFA) bypass vulnerability. An attacker who has obtained a valid administrator ID and password may be able to bypass two-factor authentication and gain unauthorized access to the administrative page.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ec-Cube | Ec-Cube | >= 4.1.0, < 4.1.2 |
Related Weaknesses (CWE)
References
- https://jvn.jp/en/jp/JVN63765888/Third Party Advisory
- https://www.ec-cube.net/info/weakness/20260209/index.phpPatchVendor Advisory
FAQ
What is CVE-2026-30777?
CVE-2026-30777 is a vulnerability with a CVSS score of 6.5 (MEDIUM). EC-CUBE provided by EC-CUBE CO.,LTD. contains a multi-factor authentication (MFA) bypass vulnerability. An attacker who has obtained a valid administrator ID and password may be able to bypass two-fac...
How severe is CVE-2026-30777?
CVE-2026-30777 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-30777?
Check the references section above for vendor advisories and patch information. Affected products include: Ec-Cube Ec-Cube.