Post
OffSequence
offseq.bsky.social
did:plc:t5t6qep2vfipbi7f54demwev
miniOrange OTP Login plugin (≤5.5.5) hit by CRITICAL auth bypass (CVE-2026-85984). Admin login possible with username only if risky options are enabled. Disable those settings ASAP. https://radar.offseq.com/threat/cve-2026-85984-cwe-287-improper-authentication-in-cyberlord92-miniorange-otp-login-...
https://radar.offseq.com/threat/cve-2026-85984-cwe-287-improper-authentication-in-cyberlord92-miniorange-otp-login-verification-and-5c3999015784c4c9
2026-09-27T03:00:27.560Z