Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-v9xm-ffx2-7h35 | ApostropheCMS MFA/TOTP Bypass via Incorrect MongoDB Query in Bearer Token Middleware |
Tue, 24 Mar 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:apostrophecms:apostrophecms:*:*:*:*:*:*:*:* |
Thu, 19 Mar 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 19 Mar 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apostrophecms
Apostrophecms apostrophecms |
|
| Vendors & Products |
Apostrophecms
Apostrophecms apostrophecms |
Wed, 18 Mar 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ApostropheCMS is an open-source content management framework. Prior to version 4.28.0, the bearer token authentication middleware in `@apostrophecms/express/index.js` (lines 386-389) contains an incorrect MongoDB query that allows incomplete login tokens — where the password was verified but TOTP/MFA requirements were NOT — to be used as fully authenticated bearer tokens. This completely bypasses multi-factor authentication for any ApostropheCMS deployment using `@apostrophecms/login-totp` or any custom `afterPasswordVerified` login requirement. Version 4.28.0 fixes the issue. | |
| Title | ApostropheCMS MFA/TOTP Bypass via Incorrect MongoDB Query in Bearer Token Middleware | |
| Weaknesses | CWE-287 CWE-305 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-19T16:12:15.179Z
Reserved: 2026-03-13T15:02:00.626Z
Link: CVE-2026-32730
Updated: 2026-03-19T16:12:06.803Z
Status : Analyzed
Published: 2026-03-18T23:17:29.370
Modified: 2026-03-24T21:34:09.467
Link: CVE-2026-32730
No data.
OpenCVE Enrichment
Updated: 2026-03-25T11:51:57Z
Github GHSA