high
CVE-2026-12695
miniOrange 2FA authentication bypass (unauthenticated MFA circumvention)
- Severity
- high
- Affected product
- miniorange-2-factor-authentication
- Affected versions
- miniorange-2-factor-authentication ≤ 5.8.5
- Fixed in
- miniorange-2-factor-authentication a release above 5.8.5
- Added to NewScan
- 2026-08-01
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
COMPONENT VERSION RANGE
NewScan fingerprints miniorange-2-factor-authentication from its response and reports this CVE when the detected version falls inside the affected range below.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →