← Terug naar overzicht

Rodauth versions before 2.46.0 contain a critical authentication bypass vulnerability in the webauthn_login route. The flaw allows already logged-in users to authenticate as any other account in the system. The root cause is improper account resolution logic that falls back to session account identifiers rather than properly validating credential binding. This means an attacker with an existing session can exploit the logic flaw to complete WebAuthn authentication as an arbitrary user. The vulnerability has been patched in Rodauth version 2.46.0. A security advisory has been published on GitHub and a fix commit is available. Users are strongly advised to upgrade immediately to mitigate the risk of account takeover.

Affected products

  • Rodauth before 2.46.0

Related CVE's

  • CVE-2026-82466

Categories

  • Identity & Access
  • Web Technologies
  • Zero-Day Vulnerabilities