Published:2026/03/05  Last Updated:2026/03/05

JVN#63765888
EC-CUBE vulnerable to multi-factor authentication bypass

Overview

EC-CUBE provided by EC-CUBE CO.,LTD. contains a multi-factor authentication (MFA) bypass vulnerability.

Products Affected

  • EC-CUBE 4.1 series versions prior to 4.1.2-p5
  • EC-CUBE 4.2 series versions prior to 4.2.3-p2
  • EC-CUBE 4.3 series versions prior to 4.3.1-p1

Description

EC-CUBE provided by EC-CUBE CO.,LTD. contains the following vulnerability.

  • Authentication bypass using an alternate path or channel (CWE-288)
    • CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N Base Score 6.9
    • CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N Base Score 4.9
    • CVE-2026-30777

Impact

An attacker who has obtained a valid administrator ID and password may be able to bypass two-factor authentication and gain unauthorized access to the administrative page.

Solution

Apply the patches
Apply the appropriate patch according to the information provided by the developer.

Vendor Status

Vendor Status Last Update Vendor Notes
EC-CUBE CO.,LTD. Vulnerable 2026/03/05 EC-CUBE CO.,LTD. website

References

JPCERT/CC Addendum

Vulnerability Analysis by JPCERT/CC

Credit

EC-CUBE CO.,LTD. reported this vulnerability to JPCERT/CC to notify users of its solution through JVN. JPCERT/CC and EC-CUBE CO.,LTD. coordinated under the Information Security Early Warning Partnership.

Other Information

JPCERT Alert
JPCERT Reports
CERT Advisory
CPNI Advisory
TRnotes
CVE CVE-2026-30777
JVN iPedia JVNDB-2026-000033