Drupal · Tfa Basic Plugins · CVE-2026-6816
**Name of the Vulnerable Software and Affected Versions**
Drupal TFA Basic Plugins versions 7.x-1.0 through 7.x-1.2
**Description**
An access bypass issue allows users possessing the administer users permission to view or generate recovery codes for other users.
**Recommendations**
Update Drupal TFA Basic Plugins to a version later than 7.x-1.2.