CVE-2019-16766 - CVE House
Back to Database
Status published High CVE-2019-16766

2FA bypass in Wagtail through new device path

Vulnerability Description

When using wagtail-2fa before 1.3.0, if someone gains access to someone's Wagtail login credentials, they can log into the CMS and bypass the 2FA check by changing the URL. They can then add a new device and gain full access to the CMS. This problem has been patched in version 1.3.0.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-16766

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Lab Digital

View all reports →

Affected Software

wagtail-2fa
Vulnerable Versions:
< 1.3.0

Timeline

Official Publish: November 29th, 2019
Last Modified: August 5th, 2024
Added to House: July 20th, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N

Weaknesses (CWE)