A significant security flaw has been found in the Drupal Simple OAuth (OAuth2) & OpenID Connect module. This vulnerability, identified as CVE-2025-12466, could allow unauthorized individuals to bypass authentication and gain access to parts of your Drupal site that should be restricted. It affects how the module handles access permissions based on user roles, posing a risk to data integrity and confidentiality.
CVE Details
This security issue impacts the Drupal Simple OAuth (OAuth2) & OpenID Connect module.
- Published: October 30, 2025
- Severity: HIGH
- Status: Analyzed
Affected Products
The vulnerability specifically affects versions of the Simple OAuth (OAuth2) & OpenID Connect module for Drupal, ranging from version 6.0.0 up to, but not including, version 6.0.7. If your Drupal installation uses any version within this range, it is potentially vulnerable.
Current Status
This vulnerability has been analyzed and publicly disclosed. Details regarding its nature and potential impact are available to help users understand and address the risk.
Severity Level
The CVE-2025-12466 vulnerability is rated with a CVSS score of 7.5, classifying it as HIGH severity. This rating indicates that exploiting this flaw could lead to significant unauthorized access. Attackers could bypass role-based access checks within your Drupal application if they manage to obtain an access token, even if the user associated with that token does not have the necessary roles assigned.
Possible Solutions
To protect your Drupal site from this authentication bypass vulnerability, it is crucial to update your Simple OAuth (OAuth2) & OpenID Connect module immediately. The recommended solution is to install the latest version available:
- Upgrade to Simple OAuth (OAuth2) & OpenID Connect version 6.0.7 or later.
Regularly updating all modules and Drupal core is a critical practice for maintaining the security of your website.
References
https://www.drupal.org/sa-contrib-2025-114


