CVE-2025-12466

Publication date

2025-10-29 23:14:51

Family

drupal

State

PUBLISHED

Description

Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Simple OAuth (OAuth2) & OpenID Connect allows Authentication Bypass.This issue affects Simple OAuth (OAuth2) & OpenID Connect: from 6.0.0 before 6.0.7.