
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-12466 is an Authentication Bypass Using an Alternate Path or Channel vulnerability (CWE-288) in the Drupal Simple OAuth (OAuth2) & OpenID Connect module. It affects versions 6.0.0 through 6.0.6 (i.e., from 6.0.0 before 6.0.7) for Drupal. The vulnerability was published on October 29, 2025, with an initial analysis completed by NIST on December 4, 2025. It carries a CVSS v3.1 base score of 7.5 (High), assessed by CISA-ADP (GitHub Advisory, Drupal Advisory).
The root cause is classified as CWE-288 — Authentication Bypass Using an Alternate Path or Channel — meaning the module exposes an alternate path or channel within its OAuth2/OpenID Connect implementation that does not enforce proper authentication checks. An unauthenticated remote attacker can exploit this over the network with low complexity and no user interaction required, by leveraging the unprotected alternate path to bypass the module's authentication mechanisms. No detailed public technical write-up or proof-of-concept code has been published as of the time of this report (GitHub Advisory, Drupal Advisory).
Successful exploitation allows an unauthenticated attacker to bypass authentication controls enforced by the Simple OAuth module, potentially gaining unauthorized access to protected resources or user sessions on the affected Drupal site. The primary impact is a high confidentiality loss, as sensitive user data, OAuth tokens, or protected content could be exposed to unauthorized parties. Integrity and availability are not directly impacted according to the CVSS assessment, but unauthorized access could serve as a foothold for further privilege escalation or data exfiltration (GitHub Advisory, Drupal Advisory).
The vendor has released a patched version: Simple OAuth (OAuth2) & OpenID Connect 6.0.7. All Drupal site administrators running versions 6.0.0 through 6.0.6 of this module should upgrade to 6.0.7 or later immediately. Additionally, organizations should audit authentication logs for anomalous access patterns, review OAuth token issuance records, and consider implementing multi-factor authentication as a defense-in-depth measure (Drupal Advisory, GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."