{"id":"CVE-2020-26136","aliases":["BIT-silverstripe-2020-26136","GHSA-mg2g-8pwj-r2j2"],"url":"https://o3.security/vulnerability/CVE-2020-26136","summary":"Authentication bypass in SilverStripe GraphQL","details":"In SilverStripe through 4.6.0-rc1, GraphQL doesn't honour MFA (multi-factor authentication) when using basic authentication.","published":"2021-06-08T20:15:08.017Z","modified":"2026-08-07T15:12:09.956049Z","cvss":{"score":6.5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"Packagist","name":"silverstripe/graphql","fixedVersion":"3.5.0"},{"ecosystem":"Packagist","name":"silverstripe/graphql","fixedVersion":"4.0.0-alpha2"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://forum.silverstripe.org/c/releases"},{"type":"ADVISORY","url":"https://www.silverstripe.org/blog/tag/release"},{"type":"ADVISORY","url":"https://www.silverstripe.org/download/security-releases/"},{"type":"EVIDENCE","url":"https://www.silverstripe.org/download/security-releases/cve-2020-26136"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T15:12:09.956049Z"}}