The Authenticator Login Project maintains a focused authentication and access-control product with a narrow but elevated exposure profile centered on critical authentication and authorization functionality. The recurring vulnerability pattern across this product reflects fundamental authentication-handling challenges: authentication bypass via alternate paths or channels, missing authentication checks on critical functions, and improper authorization boundaries are the durable weakness classes that characterize this vendor's disclosures. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Authenticator Login Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-8995CRITICAL Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Authenticator Login allows Authentication Bypass.This issue affects Authenticator Login: from 0.0.0 | Aug 15, 2025 | 9.8 | 33 | NO | NO |
CVE-2025-8093HIGH Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Authenticator Login allows Authentication Bypass.This issue affects Authenticator Login: from 0.0.0 | Oct 10, 2025 | 8.8 | 28 | NO | NO |
CVE-2025-31681CRITICAL Missing Authorization vulnerability in Drupal Authenticator Login allows Forceful Browsing.This issue affects Authenticator Login: from 0.0.0 before 2.0.6. | Mar 31, 2025 | 9.8 | 27 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Authenticator Login Project.
Media articles that mention a CVE ID that affects a product developed by Authenticator Login Project — matched by CVE ID, not by vendor name.