TAAGSOLUTIONS MyTaag Privilege Escalation Vulnerability via 2FA Deactivation

Vulnerability

A vulnerability in TAAGSOLUTIONS GmbH MyTaag versions through 2024-11-24 allows remote attackers to escalate privileges by deactivating the second factor of authentication for user accounts. This is achieved through API requests to the /session endpoint, leaving accounts unprotected.

Impact

Exploitation of this vulnerability allows for unauthorized access to user accounts by disabling two-factor authentication, bypassing an important security measure.

Reproduction

To reproduce this vulnerability, log into a MyTaag account with two-factor authentication (2FA) enabled. After logging in, a session token is received, which can be used to deactivate 2FA by sending a PUT request to the MyTaag API with the session token and a value of 0 for the 2FA field. This action removes the 2FA requirement, allowing future logins without authentication.

Remediation

Users are advised to monitor for updates from TAAGSOLUTIONS GmbH regarding this vulnerability, as a fix is expected to be released soon.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
6.6
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.