CVE-2026-82466
Last modified
CVE-2026-82466 is a high-severity vulnerability rated 8.7/10 on the CVSS scale. Rodauth before 2.46.0 contains an authentication bypass vulnerability in the webauthn_login route that allows logged-in users to authenticate as any other account. Attackers can exploit improper account resolution logic that falls back to session account identifiers instead of validating the credential binding to complete authentication as arbitrary users.. EPSS estimates a 0.34% chance of exploitation in the next 30 days.
Description
Rodauth before 2.46.0 contains an authentication bypass vulnerability in the webauthn_login route that allows logged-in users to authenticate as any other account. Attackers can exploit improper account resolution logic that falls back to session account identifiers instead of validating the credential binding to complete authentication as arbitrary users.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| jeremyevans | rodauth | < 2.46.0 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-82466?
How severe is CVE-2026-82466?
How do I fix CVE-2026-82466?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-82460Cloud Commander before 19.20.2 contains a directory traversa…9.8
- CVE-2026-82461pac4j-oidc before 6.5.6 fails to verify access token signatu…8.1
- CVE-2026-82462pac4j-oidc before 6.5.6 accepts OIDC callbacks carrying only…6.5
- CVE-2026-82463pac4j-core before 6.5.6 contains an authentication bypass vu…8.1
- CVE-2026-82464pac4j-core before 6.5.6 contains an open redirect vulnerabil…6.1
- CVE-2026-82465pac4j-saml before 6.5.6 does not require signature validatio…5.3
- CVE-2026-82467Rodauth before 2.47.0 fails to validate protocol-relative re…4.7
- CVE-2026-82468Rodauth before 2.47.0 contains a cross-site request forgery …4.7
- CVE-2026-82469Rodauth before 2.47.0 contains an authentication bypass vuln…5.4
- CVE-2026-8247An Out-of-bounds Write vulnerability in WatchGuard Fireware …8.8
- CVE-2026-82470Rodauth before 2.47.0 contains a time-based one-time passwor…5.4
- CVE-2026-82472Documenso before 2.13.0 accepts PDF file uploads on the /api…7.5
Are you affected by CVE-2026-82466?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
