{"id":"CVE-2026-32730","aliases":["GHSA-v9xm-ffx2-7h35"],"url":"https://o3.security/vulnerability/CVE-2026-32730","summary":"ApostropheCMS MFA/TOTP Bypass via Incorrect MongoDB Query in Bearer Token Middleware","details":"ApostropheCMS is an open-source content management framework. Prior to version 4.28.0, the bearer token authentication middleware in `@apostrophecms/express/index.js` (lines 386-389) contains an incorrect MongoDB query that allows incomplete login tokens — where the password was verified but TOTP/MFA requirements were NOT — to be used as fully authenticated bearer tokens. This completely bypasses multi-factor authentication for any ApostropheCMS deployment using `@apostrophecms/login-totp` or any custom `afterPasswordVerified` login requirement. Version 4.28.0 fixes the issue.","published":"2026-03-18T22:00:14.612Z","modified":"2026-08-07T11:31:10.648229734Z","cvss":{"score":8.1,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"apostrophe","fixedVersion":"4.28.0"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/32xxx/CVE-2026-32730.json"},{"type":"ADVISORY","url":"https://github.com/apostrophecms/apostrophe/security/advisories/GHSA-v9xm-ffx2-7h35"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-32730"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T11:31:10.648229734Z"}}