CVE-2026-4208
The extension fails to properly reset the generated MFA code after successful authentication. This leads to a possible MFA bypass for future login attempts by providing an empty string as MFA code to the extensions MFA provider.
More information : https://typo3.org/security/advisory/typo3-ext-sa-2026-007
