Email login otp: The security team is marking this project unsupported. (CVE-2026-16642)
The Drupal contributed project 'email_login_otp' is marked as unsupported by its security team due to an unresolved security issue. The maintainer has not fixed the known vulnerability, and no patch or remediation is currently available. Users of this project should be aware that it is no longer maintained for security and consider alternative solutions or take over maintenance.
AI Analysis
Technical Summary
The 'email_login_otp' project for Drupal has a known security vulnerability that remains unpatched because the project is officially marked as unsupported by the security team. No technical details or CVSS score are provided, and no fixes or mitigations are documented. The project is listed in the Packagist ecosystem for Drupal 8 packages. The security team recommends that users either discontinue use or assume maintenance responsibilities themselves.
Potential Impact
Because the vulnerability is unpatched and the project is unsupported, users remain exposed to potential security risks inherent in the 'email_login_otp' module. The specific impact is not detailed, but the lack of maintenance means no official fixes or mitigations are forthcoming from the original maintainers.
Mitigation Recommendations
No official fix or patch is available as the project is unsupported. Users should discontinue use of the 'email_login_otp' module or consider taking over maintenance to address the vulnerability. Refer to the Drupal security team guidance on becoming a maintainer for unsupported projects.
Email login otp: The security team is marking this project unsupported. (CVE-2026-16642)
Description
The Drupal contributed project 'email_login_otp' is marked as unsupported by its security team due to an unresolved security issue. The maintainer has not fixed the known vulnerability, and no patch or remediation is currently available. Users of this project should be aware that it is no longer maintained for security and consider alternative solutions or take over maintenance.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The 'email_login_otp' project for Drupal has a known security vulnerability that remains unpatched because the project is officially marked as unsupported by the security team. No technical details or CVSS score are provided, and no fixes or mitigations are documented. The project is listed in the Packagist ecosystem for Drupal 8 packages. The security team recommends that users either discontinue use or assume maintenance responsibilities themselves.
Potential Impact
Because the vulnerability is unpatched and the project is unsupported, users remain exposed to potential security risks inherent in the 'email_login_otp' module. The specific impact is not detailed, but the lack of maintenance means no official fixes or mitigations are forthcoming from the original maintainers.
Mitigation Recommendations
No official fix or patch is available as the project is unsupported. Users should discontinue use of the 'email_login_otp' module or consider taking over maintenance to address the vulnerability. Refer to the Drupal security team guidance on becoming a maintainer for unsupported projects.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- DRUPAL-CONTRIB-2026-085
- Osv Schema Version
- 1.7.0
- Aliases
- ["CVE-2026-16642"]
- Ecosystems
- ["Packagist:https://packages.drupal.org/8"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a6151339c2644c7f8da7511
Added to database: 07/22/2026, 23:24:35 UTC
Last enriched: 07/23/2026, 00:10:40 UTC
Last updated: 07/23/2026, 00:10:40 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.