Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.4
CVE-2026-82466: Rodauth login lets logged‑in users impersonate other accounts
CVE-2026-82466 · published 5 days ago
Summary
The Rodauth sign‑in feature allows a user who is already logged in to trick the system into acting as any other user. This happens because the software checks the wrong identifier when confirming a security key login. Update Rodauth to version 2.46.0 or later to fix the issue.
What to do
- Update jeremyevans rodauth to version 2.46.0 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | jeremyevans | rodauth | < 2.46.0 |
| Debian:14 | debian | ruby-rodauth | All versions |
Original advisory text
Rodauth before 2.46.0 Authentication Bypass via webauthn_login
Rodauth before 2.46.0 contains an authentication bypass vulnerability in the webauthn_login route that allows logged-in users to authenticate as any other account. Attackers can exploit improper account resolution logic that falls back to session account identifiers instead of validating the credential binding to complete authentication as arbitrary users.
References
- https://github.com/jeremyevans/rodauth
- https://github.com/jeremyevans/rodauth/commit/35d74a9f07b2005a8ea75fc11a6539c04f...
- https://github.com/jeremyevans/rodauth/security/advisories/GHSA-3pvr-v35r-4r75
- https://www.vulncheck.com/advisories/rodauth-before-2.46.0-authentication-bypass...
- https://security-tracker.debian.org/tracker/CVE-2026-82466 Vendor Advisory
Severity
9.4
Critical
CVSS 3.1: 8.7 (NVD)
CVSS 4.0: 9.4 (NVD)
CVSS 3.1: 8.7 (OSV)
Exploitation
EPSS <1%
Type
CWE-287Improper Authentication
Timeline
Published29 Aug 2026
Updated2 Sep 2026
First seen29 Aug 2026
Monitor software like this
Free during beta