Changing the cookies in the request to admin ones Like : Changing this to 1 and reloading gives us admin cookies and login page Cookies also bypass 2FA